ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mozilla fixes critical Firefox, Thunderbird flaws

Liam Tung ZDNet Australia

Published: 27 Mar 2008 11:34 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Mozilla has fixed seven vulnerabilities in the latest release of Firefox, with SeaMonkey and Thunderbird also affected.

Mozilla recommends users disable JavaScript in Thunderbird for the two critical flaws — MFSA 2008-15 and MFSA 2008-14 — since the email client shares the same browser engine as Firefox.

MFSA 2008-15 is a memory-corruption flaw and could allow an attacker to run arbitrary code. Mozilla has identified JavaScript errors as the source. However, it warned that an attacker could also use large image files to execute an attack.

MFSA 2008-14, meanwhile, permits an attacker to force a browser to run JavaScript code to conduct cross-site scripting and arbitrary code execution.

The two critical vulnerabilities resolved in Firefox's 2.0.0.13 release also affect Thunderbird and Mozilla's email application suite, SeaMonkey. Mozilla has identified two other "high impact" flaws — MFSA 2008-19 and MFSA 2008-18 — which could allow an attacker to create false login prompts and discover a user's identity through SSL certificates.

"It was possible to have a background tab create a borderless XUL [Mozilla's SML user-interface language] pop-up in front of the active tab in the user's browser. This technique could be used by an attacker to spoof form elements, such as a login prompt for a site opened in a different tab, and steal the user's login credentials for that site," Mozilla advised on its known-vulnerabilities web page.

Credit: Mozilla fixes critical flaws in Firefox 2.0, Thunderbird from ZDNet Australia

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

HTML, XHTML, JAVASCRIPT and CSS UI Development Media

HTML, XHTML, JAVASCRIPT and CSS UI Development Media Huxley Associates media client based in the Centre of London are looking to add a front end ...

SOFTWARE ENGINEER (J2EE, HTTP, REST, SOAP, JAVASCRIPT AJAX, TOMCAT)

SOFTWARE ENGINEER (J2EE, HTTP, REST, SOAP, JAVASCRIPT AJAX, TOMCAT) The UniProt group is looking to recruit a software engineer to support the ...

Development Team Leader - Manager, Software Developer - SQL, VB.Net, JavaScript - Glasgow, Scotland

Development Team Leader - Manager, Software Developer - SQL, VB.Net, JavaScript - Glasgow, Scotland Ref No CERI-213 Employer Description Ceridian is ...

Sentry Posts Blog

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Google sponsors open source security p...

Google has announced it is to sponsor oCERT, an open source computer emergency response team. In a blog post on Monday, Google security engineer Will Drewry said that one of the... More

Post a comment

Indian officials accuse China of cyber...

China is actively engaged in mapping India's computer networks, according to the Times of India. China is mounting "almost daily" attacks against Indian Government computer systems,... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation