Home › Web Security ›
March 27, 2009, 9:55PM
Firefox 3.0.8 fixes two code execution holes
Mozilla has released Firefox 3.0.8 to fix a pair of code execution holes that put users of the browser at risk of drive-by download attacks. It includes a fix for one of the flaws exploited during this year’s CanSecWest Pwn2Own hacker contest.
The update also fixes a separate zero-day flaw disclosed earlier this week on a public exploit site. Both issues are rated “critical,” Mozilla’s highest severity rating.
The raw details:
- MFSA 2009-13: Security researcher Nils reported via TippingPoint’s Zero Day Initiative that the XUL
treemethod_moveToEdgeShiftwas in some cases triggering garbage collection routines on objects which were still in use. In such cases, the browser would crash when attempting to access a previously destroyed object and this crash could be used by an attacker to run arbitrary code on a victim’s computer. This vulnerability does not affect Firefox 2, Thunderbird 2, or released versions of SeaMonkey. - MFSA 2009-12: Security researcher Guido Landi discovered that a XSL stylesheet could be used to crash the browser during a XSL transformation. An attacker could potentially use this crash to run arbitrary code on a victim’s computer. This vulnerability was also previously reported as a stability problem by Ubuntu community member, Andre. Ubuntu community member Michael Rooney reported Andre’s findings to Mozilla, and Mozilla community member Martin helped reduce Andre’s original testcase and contributed a patch to fix the vulnerability.
Commenting on this Article is closed.
Today's Most Popular
- Dear Jailbreaker, Apple Wants to Have a Word with You
- White House Security Czar Howard Schmidt Retiring
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
- New P2P Zeus Variant Targets Popular Sites with Bogus Offers
Most Commented Stories
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (5)
-
White House Security Czar Howard Schmidt Retiring (3)
-
Staggering Increase in Android Malware Variants, Trojan Apps (2)
-
New P2P Zeus Variant Targets Popular Sites with Bogus Offers (1)
-
Dear Jailbreaker, Apple Wants to Have a Word with You (1)
Newsletter Sign-up
Take Our Poll
The Internet Crime Complaint Center recently warned of malware targeting travelers connecting to Wi-Fi. When traveling, do you
Connect to anything
22%
Only connect to password-protected, secure connections
38%
Only use websites with HTTPS
27%
I don’t pay attention to how I access the internet while traveling
13%
Total votes: 60
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



