in

MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.

bits and bytes

Critical Vulnerabilities in FireFox, Thunderbird and Opera

Secunia Advisory SA26095 Mozilla Firefox Multiple Vulnerabilities: http://secunia.com/advisories/26095/

Description:

"Some vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to conduct spoofing and cross-site scripting attacks and potentially to compromise a user's system.

1) Various errors in the browser engine can be exploited to cause memory corruption and potentially to execute arbitrary code.

2) Various errors in the Javascript engine can be exploited to cause memory corruption and potentially to execute arbitrary code.

3) An error in the "addEventListener" and "setTimeout" methods can be exploited to inject script into another site's context, circumventing the browser's same-origin policy.

4) An error in the cross-domain handling can be exploited to inject arbitrary HTML and script code in a sub-frame of another web site."

Secunia Advisory SA26138 Opera BitTorrent Header Parsing Vulnerability: http://secunia.com/advisories/26138/

Description:

"A vulnerability has been reported in Opera, which can be exploited by malicious people to compromise a user’s system

The vulnerability is caused due to Opera using already freed memory when parsing BitTorrent headers and can lead to an invalid object pointer being dereferenced. This can be exploited to execute arbitrary code, when the user is tricked into clicking on a specially crafted BitTorrent file and then removes it via a right-click from the download pane.

The vulnerability is reported in version 9.21 on Windows. Other versions may also be affected."

Either update from within program or download manually.

Firefox v2.0.0.5:  http://www.mozilla.com/en-US/firefox/all.html

Opera v9.22:  http://www.opera.com/download/index.dml?custom=yes

Thunderbird 2.0.0.5:  http://en-us.www.mozilla.com/en-US/thunderbird/2.0.0.5/releasenotes/#download

 

Only published comments... Jul 19 2007, 12:06 PM by tashi


Copyright © is the original authors. Blog site is an independent site not sponsored by Microsoft. The Yoda blog server and the Brianna SQL server would like to thank www.ownwebnow.com and www.exchangedefender.com. They wouldn't be here and broadcasting without the generosity of Vlad Mazek and his companies.

Powered by Community Server (Commercial Edition), by Telligent Systems