Promotions
 
 
The 2nd Compotitive Attack ( 1 September - 31 Oktober 2010) … more

Perpaduan EMC CLARiiON STORAGE & CISCO UCS SERVER (Juli - Desember 2010) … more

HP Workstation Z200 + Autocad 2011 = Perfect Match … more

Lowongan Pekerjaan PT.Microreksa Infonet … more

IBM System Storage Shop and Shop (15 Mei - 27 September 2010) … more

Exclusive HP Business Data Protector Promotion with HP StorageWorks Autoloader 1/8G2 (31 Agustis 2010) … more

At Microreksa, it's not awards that we celebrate. It's consistency. Our single minded focus on being the best at what we … more

CISCO SALE and READY STOCK … more

Produktivitas Tinggi dengan Investasi Ringan … more

Enhanced Your Greatinity & Productivity … more


 
 
  News, Events & Article
 
 
25-Jun-2010
Article

Avoid Ten Vulnerabilities By Upgrading To Firefox  3.6.4

24 June, 2010

Summary:

§  These vulnerabilities affect: Firefox 3.6.3  for Windows, Linux, and Macintosh

§  How an attacker exploits it: Typically by enticing one of your users to visit a malicious web page

§  Impact: Various results; in the worst case, an attacker executes code on your user's computer, gaining complete control of it

§  What to do: Upgrade to Firefox 3.6.4, or let Firefox's automatic update do it for you

Exposure:

Yesterday, Mozilla released an advisory describing ten (count based on CVE number) vulnerabilities in Firefox 3.6.3 (and earlier versions) running on all platforms. Mozilla rates more than half of these vulnerabilities as critical;  meaning an attacker can leverage them to execute code and install software without user interaction beyond normal browsing. We summarize three of the most critical Firefox 3.6.3 vulnerabilities below:

§  XSLT related Integer Overflow Vulnerability (2010-30). Extensible Stylesheet Language Transformations (XSLT) is an XML-based language used to change one XML document into another XML document. A routine Firefox uses to sort XSLT nodes suffers from an integer overflow vulnerability that can cause memory a buffer overflow. By enticing one of your users to a maliciously crafted web page, an attacker can leverage this buffer overflow to either crash Firefox, or to execute malicious code on that user's machine, with that user's privileges. If the user happened to be a local administrator or had root privileges, the attacker would gain total control of the victim's computer.
Mozilla Impact rating: Critical

§  Four Memory Corruption Vulnerabilities (2010-26). Mozilla's update fixes four unspecified memory corruption vulnerabilities, which can at least crash Firefox. Mozilla's alert doesn't say much about these vulnerabilities, other than they lie within Firefox's browser and JavaScript engines. Mozilla presumes that, with enough effort, attackers could exploit some of these memory corruption flaws to run arbitrary code on a victim's computer. To do so, an attacker would first have to trick one of your users into visiting a maliciously crafted web page. If your user took the bait, the attacker could execute malicious code on that user's machine, with that user's privileges. If the user happened to be a local administrator or had root privileges, the attacker would gain total control of the victim's computer. 
Mozilla Impact rating: Critical

§  DOM related Buffer Overflow Vulnerability (2010-29). The Document Object Model (DOM) is a W3C specification for representing structured documents as objects, in a platform and language neutral manner. Some of Firefox's DOM code suffers from a buffer overflow vulnerability. By enticing one of your users to a maliciously crafted web page, an attacker can leverage this flaw to either crash Firefox, or to execute malicious code on that user's machine, with that user's privileges. As usually, attacker may gain full control of your users' computers if they have administrative privileges.

Mozilla's alert describes four more vulnerabilities, including another code execution flaw, a potential Cross-Site Scripting (XSS) vulnerability, and an issue that could allow an attacker to record your keystrokes, or inject extra ones. Visit Mozilla's Known Vulnerabilities page for a complete list of the vulnerabilities that Firefox 3.6.4 fixes. 

The vulnerabilities alone should convince you to upgrade, but if you need more reason, Firefox 3.6.4 also comes with a neat new feature called "plug-in isolation". This feature should significantly improve Firefox's stability. Part of Firefox's draw lies in its extensive library of third party extensions or plug-ins, which deliver extra functionality to the popular browser. Previous to plug-in isolation, these extensions or plug-ins ran within the Firefox process, which meant that if a third party plug-in crashed, Firefox would crash. With Firefox 3.6.4, plug-ins now run as external processes, so Firefox can stay running even if a plug-in crashes. If you use third party extensions and plug-ins and have experienced Firefox crashes, this new feature may lessen crashes outside of Mozilla's control.

Solution Path:

Mozilla has released Firefox 3.6.4, correcting ten security vulnerabilities. If you use Firefox in your network, we recommend that you download and deploy version 3.6.4 as soon as possible.

Note: The latest version of Firefox 3.6.x automatically informs you when a Firefox update is available. We highly recommend you keep this feature enabled so that Firefox receives its updates as soon as Mozilla releases them. To verify that you have Firefox configured to automatically check for updates, click Tools => Options => Advanced tab => Update tab. Make sure that "Firefox" is checked under "Automatically check for updates." In this menu, you can configure Firefox to always download and install any update, or if you prefer, only to inform the user that an update exists.

As an aside, attackers cannot leverage many of these vulnerabilities without JavaScript. Disabling JavaScript by default is a good way to prevent many web-based vulnerabilities. If you use Firefox, we recommend you also install the NoScript extension, which will disable JavaScript (and other active scripts) by default.

For All Users:

This attack arrives as normal-looking HTTP traffic, which you must allow through your firewall if your network users need to access the World Wide Web. Therefore, the patches above are your best solution.

Status:

The Mozilla Foundation has released Firefox 3.6.4 to fix these vulnerabilities.

References:

§  Firefox 3.6.4 Release Notes

§  Vulnerabilities Fixed in Firefox 3.6.4

This alert was researched and written by Corey Nachreiner, CISSP.


What did you think of this alert? Let us know at your.opinion.matters@watchguard.com.

More alerts and articles: log into the LiveSecurity Archive.

 

NOTE:
This e-mail was sent from an unattended mailbox. Please do not reply.

ABOUT Questiva/TailoredMail:
WatchGuard has contracted with Questiva/TailoredMail, an industry leading vendor of trusted email services, to send these emails and maintain a record of your preferences confidentially. Personal information about you is not sold or rented to Questiva/TailoredMail or to other companies. Both WatchGuard and Questiva/TailoredMail are fully committed to your privacy, as detailed in WatchGuard's privacy policy.

TO UNSUBSCRIBE: You received this e-mail because you subscribed to the WatchGuard LiveSecurity Service, which advises about virus alerts, security best practices, new hacking exploits, and more. If you no longer wish to be advised of these things, please let us know.
To unsubscribe on our web site, use our handy web form.
To unsubscribe by postal mail, write to LiveSecurity Unsubscribe, 505 5th Avenue South, Suite 500, Seattle, WA 98104 - USA. 

This email was sent to: wismin@microreksa.com

No express or implied warranties are provided for herein.  All specifications are subject to change and any expected future products, features or functionality will be provided on an if and when available basis.

Copyright 2010 WatchGuard Technologies, Incorporated. All Rights Reserved. WatchGuard, LiveSecurity and Firebox, and any other word listed as a trademark in the "Terms of Use" portion of the WatchGuard Web site that is used herein, are registered trademarks or trademarks of WatchGuard Technologies, Inc. in the United States and/or other countries. All other trademarks are the property of their respective owners. You may not modify, reproduce, republish, post, transmit, or distribute this content except as expressly permitted in writing by WatchGuard Technologies, Inc.

[ BACK ]
 

  © Copyright 2009 - design and Hosting@faberhost.com