Original URL: http://www.channelregister.co.uk/2007/11/27/firefox_update/
Mozilla released an update to its Firefox browser on Monday designed to address a trio of vulnerabilities (http://secunia.com/advisories/27725).
Firefox 2.0.0.10 (http://www.mozilla-europe.org/en/products/firefox/2.0.0.10/releasenotes/) addresses a bug in the open source browser's "jar:" protocol handle, a memory corruption vulnerability, and a potential cross-site scripting hazard.
The jar: protocol handle bug was first identified (https://bugzilla.mozilla.org/show_bug.cgi?id=369814) in February by Mozilla's Jesse Ruderman, but efforts to smite the flaw didn't materialise until security bloggers demonstrated how the vulnerability could be abused to perform various exploits, including creating a possible means for hackers to steal a victim's Gmail contacts. Mozilla prioritised a bug fix shortly after the full impact of the bug became apparent.
Short for Java Archive, the jar: protocol is used to compress Java classes and other types of files into a single file. Unfortunately, the jar: protocol handler in Firefox (prior to the fix) failed to validate the MIME type of the contents of an archive, which would then be executed in the context of a trusted site.
The latest update is the tenth from Mozilla in little more than a year since the release of Firefox 2.0 in October 2006. ®
Firefox updates, blitzes trio of critical bugs (8 February 2008)
http://www.channelregister.co.uk/2008/02/08/firefox_update/
Firefox spoofing bug raises phishing fears (4 January 2008)
http://www.channelregister.co.uk/2008/01/04/firefox_spoofing_bug/
Hey, HP laptop owners: click here to get hijacked (12 December 2007)
http://www.channelregister.co.uk/2007/12/12/hp_laptop_vuln/
Firefox version 3 makes beta (20 November 2007)
http://www.channelregister.co.uk/2007/11/20/firefox_beta_1/
Thumb twiddling Mozilla promises fix for privacy-biting bug (19 November 2007)
http://www.channelregister.co.uk/2007/11/19/upcoming_firefox_patch/
Firefox broken Jar vuln. menaces Gmail (12 November 2007)
http://www.channelregister.co.uk/2007/11/12/jar_vuln/
Minor Firefox update addresses stability glitches (2 November 2007)
http://www.channelregister.co.uk/2007/11/02/firefox_update/
Bad hair day for alternative browser users (19 October 2007)
http://www.channelregister.co.uk/2007/10/19/alt_browser_vulns/
© Copyright 2008