Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Internet & Networking > Firefox, Thunderbird & SeaMonkey

Firefox, Thunderbird & SeaMonkey Post your questions about Mozilla based products (Firefox, Thunderbird & SeaMonkey) here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 17th December 2008   #1
WindowsBBS Team Member
 
Ramona's Avatar
 
Profile:
Join Date: Dec 2001
Location: Missouri
Posts: 7,493
Computer Experience:
Experienced Learner
Ramona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation Level

My System

Mozilla Firefox 3 Multiple Vulnerabilities

TITLE:
Mozilla Firefox 3 Multiple Vulnerabilities
Quote:
SECUNIA ADVISORY ID:
SA33203

VERIFY ADVISORY:
http://secunia.com/advisories/33203/

CRITICAL:
Highly critical

IMPACT:
Security Bypass, Cross Site Scripting, Exposure of sensitive
information, System access

WHERE:
>From remote

SOFTWARE:
Mozilla Firefox 3.x
http://secunia.com/advisories/product/19089/

DESCRIPTION:
Some vulnerabilities have been reported in Mozilla Firefox, which can
be exploited by malicious people to bypass certain security
restrictions, disclose sensitive information, conduct cross-site
scripting attacks, or potentially compromise a user's system.

1) Multiple errors in the layout and JavaScript engines can be
exploited to corrupt memory and potentially execute arbitrary code.

2) An error when processing the "persist" XUL attribute can be
exploited to bypass cookie settings and uniquely identify a user in
subsequent browsing sessions.

3) Multiple errors can be exploited to bypass the same-origin policy,
disclose sensitive information, and execute JavaScript code with
chrome privileges.

For more information see vulnerabilities #4 through #10 in:
SA33184

The vulnerabilities are reported in versions prior to 3.0.5.

SOLUTION:
Update to version 3.0.5.
http://www.mozilla.com/en-US/product...=firefox-3.0.5

PROVIDED AND/OR DISCOVERED BY:
The vendor credits:
1) Daniel Veditz, Jesse Ruderman, David Baron, and Gary Kwong
2) Hish

ORIGINAL ADVISORY:
http://www.mozilla.org/security/anno...sa2008-60.html
http://www.mozilla.org/security/anno...sa2008-63.html
http://www.mozilla.org/security/anno...sa2008-64.html
http://www.mozilla.org/security/anno...sa2008-65.html
http://www.mozilla.org/security/anno...sa2008-66.html
http://www.mozilla.org/security/anno...sa2008-67.html
http://www.mozilla.org/security/anno...sa2008-68.html
http://www.mozilla.org/security/anno...sa2008-69.html

OTHER REFERENCES:
SA33184:
http://secunia.com/advisories/33184/
Download Firefox 3.0.5 here: http://www.mozilla.com/en-US/firefox/all.html
Release Notes: http://www.mozilla.com/en-US/firefox.../releasenotes/

What's New in Firefox 3.0.5

Firefox 3.0.5 fixes several issues found in Firefox 3.0.4:

Fixed several security issues.
Fixed several stability issues.
Official releases for the Bengali, Esperanto, Galician, Hindi, and Latvian languages are now available.
Replaced the End-User License Agreement with a new "Know Your Rights" info bar on initial install.
When installing multiple signed XPIs simultaneously, previous versions of Firefox would fail.
Fixed several issues found in the accessibility implementation.
Added the ability to send OS-specific system notes in the crash reporter.

Ramona is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Mozilla Firefox 3 Multiple Vulnerabilities Ramona Firefox, Thunderbird & SeaMonkey 3 2nd October 2008 07:39
Mozilla Firefox 2 Multiple Vulnerabilities Ramona Firefox, Thunderbird & SeaMonkey 0 1st October 2008 21:27
Mozilla Firefox Multiple Vulnerabilities Ramona Firefox, Thunderbird & SeaMonkey 0 24th February 2007 17:51
Mozilla / Firefox / Thunderbird Multiple Vulnerabilities Ramona Firefox, Thunderbird & SeaMonkey 0 1st March 2005 22:45
New Releases - Mozilla, Firefox, Thunderbird - Security Vulnerabilities Ramona Firefox, Thunderbird & SeaMonkey 4 15th September 2004 05:08


All times are GMT +1. The time now is 03:08.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]