This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Firefox V1.0.2 Released

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…:

Mozilla foundation discloses and fixes 3 vulns…(Update incentive)
- http://isc.sans.org/diary.php?date=2005-03-23
Updated March 24th 2005 03:54 UTC
"Mark Dowd of the ISS X-Force discovered a GIF library overflow condition that could be used to execute arbitrary code with the rights of the browser or mail client process. According to ISS:

"Graphic Interchange Format (GIF) is a common and established image standard. This image format is widely supported in applications that view images, including web browsers and email clients developed by the Mozilla Foundation. Mozilla Foundation software makes use of a common image library to render GIF images. This library contains a buffer overflow vulnerability when processing a Netscape-specific extension block in GIF images. Exploitation of this buffer overflow can lead to remote compromise of affected machines with minimal user-interaction. In order to exploit this vulnerability, an attacker would be required to induce the victim to view a web page or email message containing a maliciously-crafted GIF image."

Firefox 1.0.2, Thunderbird 1.0.2, and Mozilla Suite 1.7.6 address this and two other less serious bugs. Mozilla advisories are at:
- http://www.mozilla.org/security/announce/mfsa2005-32.html
- http://www.mozilla.org/security/announce/mfsa2005-31.html
- http://www.mozilla.org/security/announce/mfsa2005-30.html

:ph34r:
FYI…(-more- Update Incentive):

- http://secunia.com/virus_information/16634…und.exploit.31/
"…Bloodhound.Exploit.31 - Severity: 1/5 - Reported: 2005-03-30 01:09 …"

- http://www.sarc.com/avcenter/venc/data/blo…exploit.31.html
Last Updated on: March 29, 2005
"Bloodhound.Exploit.31 is a heuristic detection for the Mozilla Products Malformed GIF Buffer Overflow as described in CAN-2005-0399…"

- http://www.cve.mitre.org/cgi-bin/cvename.c…e=CAN-2005-0399
"Description: Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size."

:blink: :ph34r:
FYI…

- http://secunia.com/advisories/14820/
"Release Date: 2005-04-04
Description:
A vulnerability has been discovered in Mozilla Firefox, which can be exploited by malicious people to gain knowledge of potentially sensitive information. The vulnerability is caused due to an error in the JavaScript engine, as a "lambda" replace exposes arbitrary amounts of heap memory after the end of a JavaScript string. Successful exploitation may disclose sensitive information in memory. Secunia has constructed a test, which can be used to check if your browser is affected by this issue:
- http://secunia.com/mozilla_products_arbitr…_exposure_test/
The vulnerability has been confirmed in versions 1.0.1 and 1.0.2. Other versions may also be affected.

Solution:
Disable JavaScript support…

Mozilla bug report:
- https://bugzilla.mozilla.org/show_bug.cgi?id=288688 …"

:ph34r:
FYI…

- http://www.techweb.com/wire/security/160502235
April 07, 2005
"…"We're getting ready to wrap up this 1.0.3 release," Dotzler wrote on his blog. "I'm gonna be very cautious about calling any thing a "final" candidate, but this one feels close." The biggest fix in 1.0.3 will be to eliminate the JavaScript bug disclosed last week that leaves Firefox (and its Mozilla suite sibling) vulnerable to attack. The Foundation is planning to update Mozilla to 1.7.7 to fix the same problem…"

:blink:
FYI…

- http://www.mozillazine.org/
April 15th, 2005
"…The 1.0.3 release of Firefox has been in the pipeline for a while now. When it's finally released, this minor update will fix a critical JavaScript engine memory heap disclosure bug and some other critical security and stability bugs. The fourth set of 1.0.3 release candidate builds also introduced a security change that broke many extensions. A less drastic approach was taken for the fifth set of 1.0.3 release candidates and it was hoped that the sixth set of 1.0.3 test builds would allow all extensions that were compatible with 1.0.2 to work in 1.0.3. Clearly, that wasn't perfect though, which is why we're now up to release candidate iteration number seven. The Mozilla Foundation now plans to identify the extensions that do not function correctly with the latest 1.0.3 candidates and work with their authors to get them fixed. If all goes well, the final release of Firefox 1.0.3 should be with us shortly…"

:oops: