Mozilla Fast-Tracks Fix For Critical Firefox Flaw
Mozilla has fast-tracked a patch for a critical vulnerability affecting its flagship Firefox browser.
The patch, which was originally slated for release on March 30, fixes a vulnerability that could allow remote code execution attacks. The flaw was originally released into the VulnDisco exploit pack in February but Mozilla’s security response team did not get the details until the middle of March. Now, with the CanSecWest Pwn2Own contest just a day away, the open-source group shipped the fix and explained the problem:
Security researcher Evgeny Legerov of Intevydis reported that the WOFF decoder contains an integer overflow in a font decompression routine. This flaw could result in too small a memory buffer being allocated to store a downloadable font. An attacker could use this vulnerability to crash a victim’s browser and execute arbitrary code on his/her system.
Editor's Pick
Mozilla said support for the WOFF downloadable font format is new in Firefox 3.6 (Gecko 1.9.2), meaning that this vulnerability does not affect products built on earlier versions of the Mozilla browser engine.
A hacker known as “Nils” is planning to launch a code execution exploit against Firefox at this year’s Pwn2Own. Last year, Nils hit the trifecta with successful hacking attacks against Firefox, Internet Explorer and Safari.
Commenting on this Article is closed.
Today's Most Popular
- Anatomy of a LulzSec Attack 'Singles Out' Web 2.0 Weakness
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- Google to Notify Users of DNSChanger Infections Ahead of July 9 Deadline
- Researchers: Square Card Reader Provides Straight Line to Illicit Cash?
Most Commented Stories
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.




Comments
This flaw could result in too small a memory buffer being allocated to store a downloadable font. An attacker could use this vulnerability to crash a victim’s browser and execute arbitrary code on his/her system.sevişme