[QD-Filosofia] Critical Flaws Flagged in Mozilla, Thunderbird

Alexandre Pesserl <[email protected]>
Newsgroups gmane.org.user-groups.quilombo
Message-ID <[email protected]>
Atualizem suas versões...

[]s

Alexandre

---
http://www.internetnews.com/dev-news/article.php/3408301

*Critical Flaws Flagged in Mozilla, Thunderbird*
*By Ryan Naraine 
<http://www.internetnews.com/feedback.php/http://www.internetnews.com/dev-news/article.php/3408301>* 


The Mozilla Project has issued a warning for a series of "highly 
critical" security holes in three of its core projects, including its 
flagship Firefox Web browser and the Thunderbird e-mail client.

The vulnerabilities, which also affect the Mozilla browser, could 
potentially exploited by malicious people to conduct cross-site 
scripting attacks, access and modify sensitive information, and 
compromise a user's system.

The open-source group has already fixed the bugs and are urging users to 
upgrade to Mozilla 1.7.3 <http://www.mozilla.org/products/mozilla1.x/>, 
Firefox 1.0PR <http://www.mozilla.org/products/firefox/> and Thunderbird 
0.8 <http://www.mozilla.org/products/thunderbird/>.

The news comes just days after the open-source project issued a preview 
release of Firefox 1.0, which includes an RSS (define 
<http://inews.webopedia.com/SHARED/search_action.asp?Term=rss&Template_Name=inews.webopedia.com>) 
reader that displays "live bookmarks, a new "Find" tool and an updated 
plug-in installer.

An advisory <http://secunia.com/advisories/12526/> released by Secunia 
warned that the flaws carry a "highly critical" rating.

Secunia listed seven vulnerabilities that affect the Mozilla products, 
including various boundary errors that can be exploited to cause 
heap-based buffer overflows when a specially crafted e-mail is forwarded 
or opened.

A successful attack could lead to the execution of malicious code to 
completely hijack a vulnerable machine.

Another flaw exists where insufficient restrictions on script generated 
events on text fields can be exploited to read and write content from 
and to the clipboard.

Secunia also warned of a problem with overly long links containing a 
non-ASCII characters that can be exploited via a malicious Web site or 
e-mail to cause a buffer overflow.

"An integer overflows when parsing and displaying BMP files can 
potentially be exploited to execute arbitrary code by supplying an 
overly wide malicious BMP image via a malicious website or in an 
e-mail," the research firm said.

It also highlighted a problem with the way Mozilla allows the dragging 
of links to another window or frame. "This can be exploited by tricking 
a user on a malicious Web site to drag a specially crafted javascript 
link to another window," Secunia said, warning that a malicious attacker 
could execute script code in the context of that window. "Further 
exploitation can in combination with another unspecified vulnerability 
lead to execution of arbitrary code," the company added.


_______________________________________________
Quilombodigital-filosofia mailing list
Quilombodigital-filosofia-lWjjnNBg0S7cOli+L/M/[email protected]
http://listas.quilombodigital.org/mailman/listinfo/quilombodigital-filosofia
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.