中文网站
  Advanced Search
Read the latest Blogs from IT professionals in the field. Read and write community created documents. Need IT help? Ask our staff. Connect with your peers. Check our Tech Shop for posters, books and software tools. Home

Patched Firefox 'still vulnerable'

A patched version of Mozilla's Firefox browser released on Friday isn't quite as watertight as it should be, according to a security researcher.

On Friday, shortly after Mozilla released a patch for a high-profile directory-traversal flaw - along with nine other patches - Dutch programmer Ronald van den Heetkamp posted proof-of-concept code which he claims shows that the bug is still exploitable.

The original bug could be exploited when Firefox was running any of more than 600 add-ons to steal "session information, including session cookies and session history," according to Mozilla, which ranked it as "high" severity.

But the patch that arrived on Friday only fixes "50 percent" of the problem, according to van den Heetkamp.

"I found another information leak that is very serious because we are able to read out all preferences set in Firefox, or just open or include about every file stored in the Mozilla program files directory, and this without any mandatory settings or plugins," he wrote in an advisory.

He said the attack vector had only taken "a couple of minutes" to come up with, and that other similar holes could remain.

Among Friday's 10 Firefox patches were three for critical vulnerabilities, which could allow an attacker to read sensitive information, bypass certain security restrictions, conduct spoofing attacks, or compromise a user's system, according to Mozilla.

Reply

The content of this field is kept private and will not be shown publicly.
  • Use <!--pagebreak--> to create page breaks.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <!--pagebreak--> <img> <br> <table> <tr> <td> <tbody> <p>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
2 + 3 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.