On July 10th, I posted about a security issue in URL protocol handling on Windows. In the previous example, Internet Explorer was the entry point and Firefox was the application receiving the bad data.
Over the weekend, we learned about a new scenario that identifies ways that Firefox could also be used as the entry point. While browsing with Firefox, a specially crafted URL could potentially be used to send bad data to another application.
We thought this was just a problem with IE. It turns out, it is a problem with Firefox as well. We should have caught this scenario when we fixed the related problem in 2.0.0.5. We believe that defense in depth is the best way to protect people, so we’re investigating it now.
We are working to make sure that we are giving you as much information about pressing security issues as possible. We make real-time updates as we find out new information because we are committed to an open and transparent security process.
For more information: https://bugzilla.mozilla.org/show_bug.cgi?id=389106
Pingback from University Update - Firefox - Permanent Link to Related Security Issue in URL Protocol Handling on Windows on ::
Pingback from » Mozilla caught napping on URL protocol handling flaw | Ryan Naraine’s Zero Day | ZDNet.com on ::
Aaron Margosis
wrote on
::
Pingback from Window Snyder fesses up - Firefox also passes "bad data" - Spyware Sucks on ::
Pingback from XoftSpy SE Antispyware » Blog Archive » Window Snyder fesses up - Firefox also passes “bad data” on ::
Pingback from Firefox could also be used as the entry point | GNUCITIZEN on ::
Giorgio Maone
wrote on
::
Pingback from IE’s unescaped URLs vulnerability also present in Firefox : Mozilla Links on ::
Pingback from YouTube Elevates Top Users to Partners - BlogStuffPro.com on ::
Pingback from IE’s unescaped URLs vulnerability also present in Firefox · Get Latest Mozilla Firefox Browsers on ::
Bill Feagin
wrote on
:
Pingback from Mozilla: Firefox is flawed just like IE on ::
Pingback from Mozilla Admits Firefox Has Same Flaw as IE | CTF Blog on ::
Pingback from Techzi » Blog Archive » Mozilla: Firefox is flawed just like IE on ::
Pingback from Be:Fox » La faille critique d’exploitation du protocole URL n’est pas totalement corrigée on ::
Blackstorm
wrote on
::
Pingback from Firefox: Nuove Falle, ed Imbarazzo « Simply Security on ::
Pingback from Attack of the URL Vulnerabilities | GNUCITIZEN on ::
Pingback from It takes courage to admit your product is insecure | Security Insider on ::
Pingback from Messy URL protocol-handling drama finally winding down — Security Bytes on ::
Pingback from [SSD] Security & Development Blog » Insisto: grave riesgo amenaza a usuarios de Firefox en Windows XP on ::
asdf
wrote on
:
Pingback from Mozilla Security Blog » Blog Archives » Firefox 2.0.0.6 now available on ::
Pingback from Firefox 2.0.0.6 now available · Get Latest Mozilla Firefox Browsers on ::
Pingback from Mozilla rushes out second Firefox patch this month on ::
Pingback from Mozilla Rushes Out Another Firefox Patch « TechTitans™ on ::
Pingback from Firefox 2.0.0.6 - Yes, it’s Another Update - CyberNet News on ::
Pingback from Mozilla Firefox 2.0.0.6 Released · Get Latest Mozilla Firefox Browsers on ::
Pingback from Mozilla Firefox v2.0.0.6 is available on ::
Pingback from Mozilla Firefox v2.0.0.6 is available on ::
Pingback from Mozilla Firefox 2.0.0.6 Released on ::
Pingback from Official Blog for Goviphosting.com » Mozilla rushes out second Firefox patch this month on ::
zend
wrote on
::
Cleocin
wrote on
::
Andrea
wrote on
::
Day Spring Center
wrote on
::