Email this article   Print article 

U.S.-CERT Warns Of Rogue Code For Firefox Flaw

By Sharon Gaudin, CRN
February 28, 2007    6:56 PM ET

The U.S. Computer Emergency Response Team (CERT) issued a warning on Wednesday that a proof-of-concept code is circulating in the wild that could be vulnerability in Mozilla's Firefox browser.

The memory corruption vulnerability in Mozilla's flagship, open-source browser exists due to a flaw in the way Firefox handles freed data structures modified in the onUnload event handler, according to a U.S.-CERT advisory. That flaw can cause a memory corruption error.

Firefox, another U.S.-CERT advisory warns, does not properly handle JavaScript "onUnload" events. This vulnerability may lead to memory corruption that could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.

Mozilla's security update, which was released last week, does fix the memory corruption issue, though the company had not made that public initially.

"The Firefox 2.0.0.2 update includes fixes for the bugs that researcher Michal Zalewski reported last week, including the hostname vulnerability, cookie issue and memory corruption issue," wrote Window Snyder, Mozilla's chief security officer, in an e-mail to InformationWeek. "Due to the security fixes, we strongly recommend that all Firefox users upgrade to this latest release." The upgrade is available at this Web site.

The JavaScript onUnload event defines the actions taken when the browser exits a Web page. According to U.S.-CERT, users can download the Firefox update but they also could disable JavaScript to fend off the exploit.


Email this article   Print article 

More Security

Recent Articles

Symantec's Code Red: The Law Enforcement/Anonymous E-Mail Exchange

Law enforcement officials negotiated via e-mail for more than two weeks with an Anonymous group member trying to extort $50,000 from Symantec to keep stolen product code off the Internet.

How To Sell IT Security Services To Your Customers

Cyberattacks can cost a business thousands, even millions, of dollars, and can deal a death blow to some. Here's how IT solution providers can help guard against malicious attacks.

Cybersecurity Experts: What They Know Could Scare You

A recent report based on interviews with security experts in government, business and academia finds more than half in agreement that a worldwide arms race is taking place in cyberspace.

  More Slide Shows




Related Videos
Loading...