What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Reply to this topicStart new topic
> Firefox updates
AplusWebMaster
post Jun 17 2008, 02:01 PM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,574
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Firefox v3.0 released
- http://www.mozilla.com/firefox/

Release notes:
- http://www.mozilla.com/firefox/3.0/releasenotes/

Download:
- http://www.mozilla.com/firefox/all.html
(over 45 languages)

.

This post has been edited by AplusWebMaster: Jul 3 2008, 06:20 AM
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies
AplusWebMaster
post Jul 18 2009, 10:56 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,574
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

NEW vuln - FireFox 3.5.1 confirmed, exploit PoC, no patch
- http://isc.sans.org/diary.html?storyid=6829
Last Updated: 2009-07-18 15:04:23 UTC - "Various analysts and sites have recently confirmed a vulnerability is present in FireFox 3.5.1 that has had exploit PoC released. When exploited, the vulnerability can lead to system compromise or induce a DOS. No Patch is available."
Mozilla Firefox 3.5 Unicode Data Remote Stack Buffer Overflow Vulnerability
> http://www.securityfocus.com/bid/35707/
CVE-2009-2479
> http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2009-2479
Last revised: 07/16/2009
CVSS v2 Base Score: 10.0 (HIGH)
>> http://xforce.iss.net/xforce/xfdb/51729
Reported: July 15, 2009
>> http://www.milw0rm.com/exploits/9158
[2009-07-15]

milw0rm 9158 “stack overflow” crash not exploitable (CVE-2009-2479)
- http://blog.mozilla.com/security/2009/07/1...-cve-2009-2479/
07.19.09 - "In the last few days, there have been several reports (including one via SANS) of a bug in Firefox related to handling of certain very long Unicode strings. While these strings can result in crashes of some versions of Firefox, the reports by press and various security agencies have incorrectly indicated that this is an exploitable bug. Our analysis indicates that it is -not-, and we have seen no example of exploitability... we believe that the IBM report is in error, and that the severity rating in the National Vulnerability Database report is incorrect. We have contacted them and hope to resolve the inaccuracies shortly."

ph34r.gif ph34r.gif

This post has been edited by AplusWebMaster: Jul 19 2009, 06:52 PM
Reason for edit: Added Mozilla security blog reply...
Go to the top of the page
 
+Quote Post

Posts in this topic
- AplusWebMaster   Firefox updates   Jun 17 2008, 02:01 PM
- - AplusWebMaster   Suggested reading prior to install: Release notes...   Jun 17 2008, 02:49 PM
- - AplusWebMaster   FYI... Firefox vuln - unpatched - http://secunia....   Jun 19 2008, 04:14 AM
- - AplusWebMaster   FYI... - http://preview.tinyurl.com/47o8yg June 2...   Jun 27 2008, 11:52 AM
- - AplusWebMaster   FYI... Firefox v2.0.0.15 released From an admin ...   Jul 1 2008, 04:30 PM
- - AplusWebMaster   FYI... Firefox v2.0.0.16 released From an admin ...   Jul 16 2008, 12:20 AM
- - AplusWebMaster   FYI... Firefox v3.0.1 released - http://www.mozil...   Jul 16 2008, 05:01 PM
- - AplusWebMaster   FYI... Firefox v3.0.2 released - http://www.mozil...   Sep 23 2008, 07:40 PM
- - AplusWebMaster   FYI... Firefox v3.0.3 released - http://en-us.www...   Sep 26 2008, 06:03 PM
- - AplusWebMaster   FYI... Firefox v3.0.4 - v2.0.0.18 released From ...   Nov 12 2008, 06:35 PM
- - AplusWebMaster   FYI... Firefox v3.0.5 released - http://www.mozil...   Dec 16 2008, 05:19 PM
- - AplusWebMaster   FYI... Firefox v2.0.0.20 released - http://www.mo...   Dec 19 2008, 08:16 AM
- - AplusWebMaster   FYI... Firefox v3.0.6 released From an admin acc...   Feb 3 2009, 06:56 PM
- - AplusWebMaster   FYI... Firefox v3.0.7 released From an admin acc...   Mar 4 2009, 07:51 PM
- - AplusWebMaster   FYI... Firefox v3.0.8 released From an admin acc...   Mar 28 2009, 04:20 AM
- - AplusWebMaster   FYI... Firefox v3.0.9 released From an admin acc...   Apr 21 2009, 07:58 PM
- - AplusWebMaster   FYI... Firefox v3.0.10 released From an admin ac...   Apr 28 2009, 04:12 AM
- - AplusWebMaster   FYI... Firefox v3.0.11 released From an admin ac...   Jun 11 2009, 04:21 PM
- - AplusWebMaster   FYI... - http://support.mozilla.com/en-US/kb/Upgr...   Jun 30 2009, 04:25 PM
- - AplusWebMaster   FYI... Firefox memory corruption vuln - unpatched...   Jul 14 2009, 03:55 AM
- - AplusWebMaster   FYI... Firefox v3.5.1 released From an admin acc...   Jul 16 2009, 08:30 PM
- - AplusWebMaster   FYI... NEW vuln - FireFox 3.5.1 confirmed, exploi...   Jul 18 2009, 10:56 AM
- - AplusWebMaster   FYI... Firefox v3.0.12 released From an admin acc...   Jul 21 2009, 07:03 PM
- - AplusWebMaster   FYI... Firefox v3.5.2 released From an admin ac...   Aug 8 2009, 10:47 AM
- - AplusWebMaster   FYI... Firefox will check Flash... - http://blog....   Sep 4 2009, 04:44 PM
- - AplusWebMaster   FYI... Firefox v3.5.3 released From an admin acc...   Sep 9 2009, 07:16 PM
- - AplusWebMaster   FYI... - http://www.channelregister.co.uk/2009/09...   Sep 17 2009, 05:04 AM
- - AplusWebMaster   FYI... Firefox blocks MS add-on to tighten securi...   Oct 18 2009, 05:41 AM
- - AplusWebMaster   'Wish somebody would make up their mind! ...   Oct 19 2009, 07:40 AM
- - AplusWebMaster   FYI... - http://www.java.com/en/download/faq/fire...   Oct 21 2009, 11:24 AM
- - AplusWebMaster   FYI... Firefox v3.5.4 released From an admin acc...   Oct 27 2009, 08:07 PM
- - AplusWebMaster   FYI... Firefox v3.5.5 released From an admin acc...   Nov 5 2009, 10:57 PM
- - AplusWebMaster   FYI... Firefox v3.5.6 released From an admin acc...   Dec 16 2009, 05:28 AM
- - AplusWebMaster   FYI... Firefox v3.5.7 released From an admin acc...   Jan 5 2010, 11:42 PM
- - AplusWebMaster   FYI... Firefox v.3.6 released - http://www.mozill...   Jan 25 2010, 08:49 PM
- - AplusWebMaster   FYI... From an admin account, start Firefox, then...   Feb 18 2010, 05:38 AM
- - AplusWebMaster   FYI... Firefox v3.6.2 - http://secunia.com/adviso...   Today, 05:42 AM


Reply to this topicStart new topic

 


RSS Time is now: 20th March 2010 - 11:15 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy