internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

FireFox Fixes by the Dozen
Mozilla Updates Firefox to v1.5.0.4
Sean Michael Kerner

Mozilla has updated its flagship FireFox browser to version 1.5.0.4 and, in the process, fixed no less than 12 flaws.

Five of the vulnerabilities are classified by Mozilla as "critical" and two are rated as "high."

Among the "critical" vulnerabilities is "Mozilla Foundation Security Advisory 2006-32," which fixes a potential memory corruption vulnerability.

"Mozilla team members discovered several crashes during testing of the browser engine showing evidence of memory corruption that we presume is exploitable, "the Mozilla advisory said.

A critical privilege escalation exploit also got plugged in Firefox 1.5.0.4 that could have been exploited via persisted XUL attributes that are associated with an incorrect URL.

XUL (define)is an acronym for an XML-based User Interface Language (pronounced "zuul") and is Mozilla's language for creating its user interface.

Mozilla Foundation Security Advisory 2006-37 is titled,"Remote compromise via content-defined setter on object prototypes." It is also labeled as "critical."

Mozilla's advisory on the potential XUL vulnerability as well as the object prototypes and a few other items were among 12 publicly reported vulnerabilities. But more details were hard to come by as of presstime.

The reason?

"Exploit details withheld until sufficient users upgrade to a fixed version." Mozilla's advisories said.

However, at least one of the vulnerabilities that Mozilla rated as "high" included more detail. Mozilla Foundation Security Advisory 2006-33, titled "HTTP response smuggling" explains how Firefox could be fooled by a malicious proxy server's response to a page request.

"The content of that response could be a Web page that could steal login cookies or other sensitive data if the user has an account at the victim site," Mozilla's advisory continued.

Firefox 1.5.04 also fixed a vulnerability that was supposed to have been fixed in the 1.5.0.2 update, which was released in mid-April of this year.

Mozilla Foundation Security Advisory 2006-41 is an update to MFSA 2006-23 titled,"File stealing by changing input type." That particular flaw, according to the original advisory, could allow a malicious Web site operator to potentially steal any local file on a user's PC as long as they could guess their user name. The attack vector would be via a pre-filled text input box that could then be turned into a file upload control.

However, the fix that Mozilla introduced did not completely address the issue.

"In Firefox 1.5.0.2, it is still possible to pre-fill a text input control with the path to a file at a known location and then change the type of the input control to a file upload control without having the value reset as intended," Mozilla's advisory said.

The 1.5.0.4 release is the fourth point upgrade for Firefox this year. Version 1.5.0.1 was released in February; 1.5.0.2 in April and the 1.5.0.3 release at the beginning of May. Mozilla's next generation Firefox's 2.0 release is now an Alpha 3, and is expected to go to full release later this year.

News courtesy of internetnews.com

June 2, 2006

Download Mozilla Firefox Now!Download

Download Internet Explorer 7 Now!Download

View All Web Browsers

Contents:
1. Mozilla Updates Firefox to v1.5.0.4


Additional Articles:

  • Mozilla's Newest FireFox Takes Flight
  • Browser Wars v.2004: Part 1
  • Browser Wars v.2004: Part 2
  • Mozilla Firefox's Volunteer Launch Brigade
  • Rise of the Underdog Browser
  • Firefox Makes It Official
  • Add-ons Extend Firefox Growth
  • Getting the Most Out of Firefox
  • Firefox Thankful for Strong November
  • Firefox, Others at Phishing Risk
  • Browser Wars: Who's Winning, Who's Losing
  • Firefox Torches Competition for Enterprise Linux Award
  • Mozilla Updates Firefox
  • New Firefox Vulnerability Pushes Latest Update
  • Firefox Update Patches Three in Time
  • JavaScript Flaw Hits Mozilla Users
  • Firefox Popularity Spurs Mozilla Traffic Surge
  • Beware the Browser Backlash
  • Another Flaw Found in Mozilla
  • Google Extends Firefox
  • New Firefox Fixes Holes
  • Firefox Advocate Site Hit by Hackers
  • Mozilla Goes for More Green
  • IBM Donates Code to Firefox
  • Firefox Losing Its Grip?
  • Mozilla Under Fire
  • Mozilla FireFox DoS Exploit Code Released
  • Firefox: Nearly a Year Old And Now 100M Strong
  • Happy Birthday, Firefox 1.0
  • Firefox Upgrade Near
  • Firefox at Critical Mass?
  • New Firefox Kills Bugs
  • A Word-Wise Firefox Extension
  • Mozilla Plugs Firefox Bugs
  • Goooaaal! Google, Mozilla Kick In Soccer Fix
  • Firefox 2.0: Mozilla's Tabs Overfloweth
  • Firefox 1.5.0.5 Fixes JavaScript Flaws
  • Firefox Is Doing So Well It's Now a Malware Target
  • Firefox 2.0 Beta Tweaking Its Look
  • The Firefox, IE Race to The Finish
  • Firefox Hits Seventh Heaven
  • Firefox 2.0 Release Candidate Goes Live Today
  • Double Deuce as Firefox 2.0 Nears Completion
  • Mozilla Fine-Tunes for Final Release of Firefox 2
  • Firefox 2.0 Released: 'Bon Echo' Lives!
  • Firefox 3.0 Already?
  • Path to Firefox 2.0 Is Cleared
  • Our Phishing Filter Is Better Than Yours!
  • Phishers Lurk for Firefox 2.0 Password Manager
  • Mozilla Fixes Firefox Flaws, Misses One
  • Mozilla Rakes In $53M
  • Mozilla Patches Some Firefox Holes
  • Mozilla Security: More Than Meets the 'Aye'
  • One Flaw and a First for Latest Firefox Update
  • Firefox 1.5 Gets Its Last Update
  • Firefox at Risk Because of Internet Explorer?
  • Firefox Fixes IE Flaws
  • Mozilla Firefox Still at Risk
  • Will Mozilla's Fuzzer Break the Web?
  • Mozilla Updates Firefox Ahead of Black Hat
  • Flaw Still Shadows Firefox
  • Firefox Gets BitTorrent
  • Firefox Gets QuickTime Fix
  • Mozilla Separating Browser from the App
  • Firefox Fixes Cross-Site Flaws
  • Firefox Breaks Web Canvas
  • Warning on Spoofed Login Windows in Firefox
  • Mozilla Update Quashes Slew of Firefox Flaws
  • Firefox Update Tackles Pair of Critical Bugs
  • Will Design Flaws Flunk Firefox?


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs