myITforum.com

Welcome to myITforum.com Sign in | Join | Help
in Search

Harry Waldron - My IT Forums Blog

Sharing Security Developments, and Best Practices for corporate and home users

Mozilla releases security updates for browser & email products

  Users should upgrade to the latest version.  I use Firfox 1.0.2 as a complementary browser on all my Windows systems.  For the 1st time I experimented with the new upgrade feature and it worked in an accurate manner (although I don't have special themes or extensions installed).  The clean installation technique is also noted in the link at the bottom. 

Mozilla releases security updates for browser & email products
http://isc.sans.org/diary.php?date=2005-03-23

Mark Dowd of the ISS X-Force discovered a GIF library overflow condition that could be used to execute arbitrary code with the rights of the browser or mail client process. Mozilla Foundation software makes use of a common image library to render GIF images. This library contains a buffer overflow vulnerability when processing a Netscape-specific extension block in GIF images.

Exploitation of this buffer overflow can lead to remote compromise of affected machines with minimal user-interaction. In order to exploit this vulnerability, an attacker would be required to induce the victim to view a web page or email message containing a maliciously-crafted GIF image."  Firefox 1.0.2, Thunderbird 1.0.2, and Mozilla Suite 1.7.6 address this and two other less serious bugs.

Mozilla advisories:
http://www.mozilla.org/security/announce/mfsa2005-32.html
http://www.mozilla.org/security/announce/mfsa2005-31.html
http://www.mozilla.org/security/announce/mfsa2005-30.html

Downloads Available at:
http://www.mozilla.org/

More details and installation techniques for Firefox 1.0.2
http://forums.mozillazine.org/viewtopic.php?t=240048

Comments

No Comments
Powered by Community Server (Commercial Edition), by Telligent Systems