internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

A Trio of Memory Flaw Fixes for Mozilla Firefox 3
3 Critical Vulnerability Patches Part of Firefox 3.0.7 Update
Sean Michael Kerner

While rivals are pushing the latest editions of their own browsers, Mozilla is getting its own house in order with an update to its open source Firefox Web browser that locks down at least five vulnerabilities, three of which it warned are critical.

The Mozilla Firefox 3.0.7 update also fixes a number non-security bugs that had affected browser stability.

The update comes at the same time that Mozilla's developers continue to ramp up their oft-delayed, next-generation Firefox 3.1 release, as competitors push out their own new browsers' betas with Microsoft Internet Explorer 8 (IE8), Apple Safari 4 and Google Chrome 2.

For the critical fixes in Firefox 3.07, memory related issues are a big concern. In its Mozilla Foundation Security Advisory 2009-07 for one of the fixes, Mozilla addresses what it describes generically as, "Crashes with evidence of memory corruption." The crash conditions potentially could have enabled an attacker to execute arbitrary code on a vulnerable browser installation.

Mozilla provides more detail on another memory crash condition, through a separate critical advisory dealing with PNG (define) images. According to Mozilla, there were memory safety hazards in the libraries that Mozilla was using to handle PNG files. As a result, an attacker could potentially have generated a malicious PNG image that could trigger a crash, thereby enabling the attacker to execute unauthorized code.

A third critical security vulnerability repaired in the update is also memory-related and has to do with how Mozilla manages memory relating to user-interface components — specifically page elements based on Extensible User-Interface Language, or XUL (define).

"The vulnerability was caused by improper memory management of a set of cloned XUL ... elements which were linked as a parent and child," Mozilla stated in its advisory. "After reloading the browser on a page with such linked elements, the browser would crash when attempting to access an object which was already destroyed."

Also fixed in the Firefox 3.0.7 is a cross-site scripting issue rated by Mozilla as having a "high" impact. According to Mozilla's advisory, the vulnerability could have enabled an attacking Web site to take data from users who are authenticated on another site.

"A Web site could use nsIRDFService and a cross-domain redirect to steal arbitrary XML data from another domain, a violation of the same-origin policy," Mozilla said.

Spoofing, which is an issue that could lead to phishing attacks, is also addressed in the Firefox 3.0.7 update.

"Mozilla contributor Masahiro Yamada reported that certain invisible control characters were being decoded when displayed in the location bar, resulting in fewer visible characters than were present in the actual location," Mozilla's advisory stated. "An attacker could use this vulnerability to spoof the location bar and display a misleading URL for their malicious Web page."

The Firefox 3.0.7 update is Mozilla's second Firefox 3.x update of the year and follows the 3.0.6 update by nearly a month.

On the development side, Mozilla developers are still working on Firefox 3.1, which will introduce new performance and security features. Currently stalled at Beta 2, a Beta 3 release is in the works with Beta 4 to follow.

A new JavaScript engine called TraceMonkey is likely to be the marquee feature in the upcoming browser. JavaScript performance has emerged as a key metric on which browser vendors are now competing, with Mozilla, Apple, and Google in particular placing an increasing amount of focus on squeezing extra speed out of their browsers' engines.

News courtesy of internetnews.com

March 5, 2009

Download Mozilla Firefox 3!Download

Download Safari Now!Download

View All Web Browsers

Contents:
1. 3 Critical Vulnerability Patches Part of Firefox 3.0.7 Update


Additional Articles:

  • New Firefox 2.0 Features Line Up for Release
  • Firefox 2.0 Bakes in Anti-Phish Antidote
  • 'Bon Echo' Becomes Firefox Beta 1
  • A Coverity Eye on Firefox Code
  • Firefox 3 in Alpha 2 Release
  • Firefox 3.0 Development Continues in 'Gran' Style
  • Firefox 3 Gets Some FUEL
  • Firefox 3 Goes Places With Alpha 5
  • Mozilla Closing In on Firefox 3
  • Mozilla Aims at Cross-Site Scripting with Firefox 3
  • Firefox 3 Secures Extensions
  • Firefox 3 Beta 1 Enters Test Run
  • Firefox 3 Beta 2 Arrives Early
  • Mozilla Aims to Weave a New Web
  • Mozilla to Apple: Show Your Hand
  • Firefox 3: The Semantic Web Browser?
  • Mozilla Re-Thinking Firefox EULA
  • Mozilla CTO Sees an Upside to the Browser Wars
  • Firefox Fixes New and Older Versions
  • Mozilla Jetpack Could Speed Firefox Add-on Efforts
  • Firefox 3.5: How Soon and How Big a Deal?
  • Mozilla Fixes Firefox Flaws as 3.5 Release Nears
  • Why Firefox Doesn't Take Google Chrome Features
  • Firefox 3.5 Set to Roll Out Today
  • Firefox 3.5.1 Update Coming in July
  • Mozilla Patches Firefox for Black Hat Flaws
  • Firefox 3.6 Reaches Alpha Release
  • Mozilla to Update Firefox for Flash Security
  • Mozilla Firefox 3.6 Gets Oriented
  • Firefox 3.5.4 Beta Here Now, v3.6 on the Way
  • Mozilla Blocks then Unblocks Microsoft Add-ons for Firefox
  • Mozilla Firefox 3.6 - A Minor Update?
  • Mozilla Updates Firefox Security, 3.6 Beta on Deck
  • Firefox 3.6 Beta 1 Makes the Rounds
  • Mozilla Updates Firefox 3.5.5 for 'Annoying' Bugs
  • Firefox Tops Vulnerability List
  • Looking Back as Mozilla Firefox Turns Five
  • Mozilla's New Firefox Beta a Bug-Stomping Spree
  • New Mozilla Firefox 3.6 Beta Fixes 83 Bugs


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs