internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
QuickTime for Windows
Ad-Aware 2008 Free
Internet Explorer 8
Adobe Flash Player
Paint Shop Pro
Windows Live Suite
AVG Anti-Virus Free
Winamp
Spybot Search and Destroy

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Firefox Fixes Cross-Site Flaws
Firefox 2.0.0.10 Update Fixes Nagging Security Issues
Sean Michael Kerner

If you're a Mozilla Firefox user, don't be surprised to get an update notice when you open your browser this morning.

Yet again, Mozilla developers have pushed out an update for Firefox that aims to fix nagging security issues. Firefox 2.0.0.10 takes a kick at dealing with a particularly nasty Cross-Site Scripting (XSS) flaw that had been publicly reported months ago.

Mozilla's security advisory describes the XSS flaw as being related to the "jar: URI" scheme, which is a mechanism to support digitally signed Web pages and allows those pages to load ZIP archives.

In February, Mozilla staffer Jesse Rudderman publicly reported in Bugzilla entry 369814 that "any site that allows image uploads (e.g. avatar images) without binary content sniffing is likely to be vulnerable to XSS ... as a result. An attacker would only have to upload a malicious [ZIP] file to the site and get users to follow a 'jar:' link."

Earlier this month, however, Mozilla developers reconsidered the flaw's severity and its ability to be exploited when noted security research Michal Zalewski revealed that the problem could affect a large part of the Web.

"Please note that the vulnerability is more severe and more difficult to mitigate than initially indicated; it does not require the attacked site to host a malicious JAR file, as the security context is not properly updated on 302 redirects," Zalewski wrote in a Bugzilla entry.

Mozilla's advisory today also notes that a published proof-of-concept shows the flaw could have been used to steal the Gmail contacts of logged-in Gmail users.

Firefox 2.0.0.10 also fixes a vulnerability that could have enabled Cross-Site Request Forgery (CSRF) attacks. The flaw is related to how Firefox handles referrer headers, which could potentially be spoofed by an attacker.

"When navigation occurs due to setting window.location, the Referrer header is supposed to reflect the address of the content which initiated the script," Mozilla explained in its advisory. "Instead, the referrer was set to the address of the window (or frame) in which the script was running, and this vulnerability arises from that tiny difference."

There are also three fixes in Firefox 2.0.0.10 for memory corruption issues that could potentially have led to arbitrary code execution.

Today's update marks the latest in a breakneck cycle of updates for Firefox 2.x. The new 2.0.0.10 release follows Mozilla 2.0.0.9 update by less than a month. The 2.0.0.9 update itself had followed its predecessor 2.0.0.8 by barely two weeks.

All told, Mozilla has released nine updates for Firefox 2.x in the 2007 calendar year.

On the functionality front, Mozilla is moving forward with its next generation browser, Firefox 3. Last week, the open source group released Beta 1 which includes new protection for Cross-Site Scripting attacks among its features.

News courtesy of internetnews.com

November 28, 2007

Download Mozilla Firefox 2!Download

Download Mozilla Firefox 3!Download

View All Web Browsers

Contents:
1. Firefox 2.0.0.10 Update Fixes Nagging Security Issues


Additional Articles:

  • Mozilla's Newest FireFox Takes Flight
  • Browser Wars v.2004: Part 1
  • Browser Wars v.2004: Part 2
  • Mozilla Firefox's Volunteer Launch Brigade
  • Rise of the Underdog Browser
  • Firefox Makes It Official
  • Add-ons Extend Firefox Growth
  • Getting the Most Out of Firefox
  • Firefox Thankful for Strong November
  • Firefox, Others at Phishing Risk
  • Browser Wars: Who's Winning, Who's Losing
  • Firefox Torches Competition for Enterprise Linux Award
  • Mozilla Updates Firefox
  • New Firefox Vulnerability Pushes Latest Update
  • Firefox Update Patches Three in Time
  • JavaScript Flaw Hits Mozilla Users
  • Firefox Popularity Spurs Mozilla Traffic Surge
  • Beware the Browser Backlash
  • Another Flaw Found in Mozilla
  • Google Extends Firefox
  • New Firefox Fixes Holes
  • Firefox Advocate Site Hit by Hackers
  • Mozilla Goes for More Green
  • IBM Donates Code to Firefox
  • Firefox Losing Its Grip?
  • Mozilla Under Fire
  • Mozilla FireFox DoS Exploit Code Released
  • Firefox: Nearly a Year Old And Now 100M Strong
  • Happy Birthday, Firefox 1.0
  • Firefox Upgrade Near
  • Firefox at Critical Mass?
  • New Firefox Kills Bugs
  • A Word-Wise Firefox Extension
  • Mozilla Plugs Firefox Bugs
  • FireFox Fixes by the Dozen
  • Goooaaal! Google, Mozilla Kick In Soccer Fix
  • Firefox 2.0: Mozilla's Tabs Overfloweth
  • Firefox 1.5.0.5 Fixes JavaScript Flaws
  • Firefox Is Doing So Well It's Now a Malware Target
  • Firefox 2.0 Beta Tweaking Its Look
  • The Firefox, IE Race to The Finish
  • Firefox Hits Seventh Heaven
  • Firefox 2.0 Release Candidate Goes Live Today
  • Double Deuce as Firefox 2.0 Nears Completion
  • Mozilla Fine-Tunes for Final Release of Firefox 2
  • Firefox 2.0 Released: 'Bon Echo' Lives!
  • Firefox 3.0 Already?
  • Path to Firefox 2.0 Is Cleared
  • Our Phishing Filter Is Better Than Yours!
  • Phishers Lurk for Firefox 2.0 Password Manager
  • Mozilla Fixes Firefox Flaws, Misses One
  • Mozilla Rakes In $53M
  • Mozilla Patches Some Firefox Holes
  • Mozilla Security: More Than Meets the 'Aye'
  • One Flaw and a First for Latest Firefox Update
  • Firefox 1.5 Gets Its Last Update
  • Firefox at Risk Because of Internet Explorer?
  • Firefox Fixes IE Flaws
  • Mozilla Firefox Still at Risk
  • Will Mozilla's Fuzzer Break the Web?
  • Mozilla Updates Firefox Ahead of Black Hat
  • Flaw Still Shadows Firefox
  • Firefox Gets BitTorrent
  • Firefox Gets QuickTime Fix
  • Mozilla Separating Browser from the App
  • Firefox Breaks Web Canvas
  • Warning on Spoofed Login Windows in Firefox
  • Mozilla Update Quashes Slew of Firefox Flaws
  • Firefox Update Tackles Pair of Critical Bugs




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers