USN-930-6: Firefox and Xulrunner vulnerability

Referenced CVEs: 
CVE-2010-2755

Description: 
===========================================================
Ubuntu Security Notice USN-930-6 July 26, 2010
firefox, firefox-3.0, xulrunner-1.9.2 vulnerability
CVE-2010-2755
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 9.04
Ubuntu 9.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 9.04:
abrowser 3.6.8+build1+nobinonly-0ubuntu0.9.04.1
firefox-3.0 3.6.8+build1+nobinonly-0ubuntu0.9.04.1
xulrunner-1.9.2 1.9.2.8+build1+nobinonly-0ubuntu0.9.04.1

Ubuntu 9.10:
abrowser 3.6.8+build1+nobinonly-0ubuntu0.9.10.1
firefox-3.5 3.6.8+build1+nobinonly-0ubuntu0.9.10.1
xulrunner-1.9.2 1.9.2.8+build1+nobinonly-0ubuntu0.9.10.1

After a standard system upgrade you need to restart Firefox and any
applications that use Xulrunner to effect the necessary changes.

Details follow:

USN-957-1 fixed vulnerabilities in Firefox and Xulrunner. Daniel Holbert
discovered that the fix for CVE-2010-1214 introduced a regression which did
not properly initialize a plugin pointer. If a user were tricked into
viewing a malicious site, a remote attacker could use this to crash the
browser or run arbitrary code as the user invoking the program.
(CVE-2010-2755)

This update fixes the problem.

Original advisory details:

If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)

Several flaws were discovered in the browser engine of Firefox. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,
CVE-2010-1202, CVE-2010-1203)

A flaw was discovered in the way plugin instances interacted. An attacker
could potentially exploit this and use one plugin to access freed memory from a
second plugin to execute arbitrary code with the privileges of the user
invoking the program. (CVE-2010-1198)

An integer overflow was discovered in Firefox. If a user were tricked into
viewing a malicious site, an attacker could overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1196)

Martin Barbella discovered an integer overflow in an XSLT node sorting
routine. An attacker could exploit this to overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1199)

Michal Zalewski discovered that the focus behavior of Firefox could be
subverted. If a user were tricked into viewing a malicious site, a remote
attacker could use this to capture keystrokes. (CVE-2010-1125)

Ilja van Sprundel discovered that the ‘Content-Disposition: attachment’
HTTP header was ignored when ‘Content-Type: multipart’ was also present.
Under certain circumstances, this could potentially lead to cross-site
scripting attacks. (CVE-2010-1197)

Amit Klein discovered that Firefox did not seed its random number generator
often enough. An attacker could exploit this to identify and track users
across different web sites. (CVE-2008-5913)

Articoli Correlati

  • No Related Posts

USN-958-1: Thunderbird vulnerabilities

Referenced CVEs: 
CVE-2010-0654, CVE-2010-1205, CVE-2010-1211, CVE-2010-1212, CVE-2010-1213, CVE-2010-2752, CVE-2010-2753, CVE-2010-2754

Description: 
===========================================================
Ubuntu Security Notice USN-958-1 July 26, 2010
thunderbird vulnerabilities
CVE-2010-0654, CVE-2010-1205, CVE-2010-1211, CVE-2010-1212,
CVE-2010-1213, CVE-2010-2752, CVE-2010-2753, CVE-2010-2754
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 10.04 LTS:
thunderbird 3.0.6+build2+nobinonly-0ubuntu0.10.04.1

After a standard system update you need to restart Thunderbird to make
all the necessary changes.

Details follow:

Several flaws were discovered in the browser engine of Thunderbird. If a
user were tricked into viewing malicious content, a remote attacker could
use this to crash Thunderbird or possibly run arbitrary code as the user
invoking the program. (CVE-2010-1211, CVE-2010-1212)

An integer overflow was discovered in how Thunderbird processed CSS values.
An attacker could exploit this to crash Thunderbird or possibly run
arbitrary code as the user invoking the program. (CVE-2010-2752)

An integer overflow was discovered in how Thunderbird interpreted the XUL
element. If a user were tricked into viewing malicious content, a remote
attacker could use this to crash Thunderbird or possibly run arbitrary code
as the user invoking the program. (CVE-2010-2753)

Aki Helin discovered that libpng did not properly handle certain malformed
PNG images. If a user were tricked into opening a crafted PNG file, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-1205)

Yosuke Hasegawa discovered that the same-origin check in Thunderbird could
be bypassed by utilizing the importScripts Web Worker method. If a user
were tricked into viewing malicious content, an attacker could exploit this
to read data from other domains. (CVE-2010-1213)

Chris Evans discovered that Thunderbird did not properly process improper
CSS selectors. If a user were tricked into viewing malicious content, an
attacker could exploit this to read data from other domains.
(CVE-2010-0654)

Soroush Dalili discovered that Thunderbird did not properly handle script
error output. An attacker could use this to access URL parameters from
other domains. (CVE-2010-2754)

Articoli Correlati

  • No Related Posts

Accordo tra quindici nazioni per combattere il terrorismo informatico

Washington, 17 lug. – (Adnkronos/Washington Post) – Un impegno comune per combattere la minaccia del ciberterrorismo. E’ lo storico impegno assunto da un gruppo di 15 nazioni tra cui Stati Uniti, Cina e Russia, che per la prima volta hanno espresso la volonta’ comune di ridurre la loro capacita’ di minacciare le reti digitali di altri stati con attacchi ciberterroristici. L’accordo, spiega il Washington Post, e’ stato raggiunto questa settimana all’Onu, e prevede un maggior ruolo delle Nazioni Unite nella creazione delle norme di comportamento comuni nel ciberspazio e un aumento della cooperazione tra gli stati nell’elaborazione delle legislazioni nazionali e delle strategie di sicurezza informatica.

Articoli Correlati

Il governo inglese ingaggia esperti in sicurezza informatica: proteggeranno il Paese dagli attacchi web

Il ministero dell’Interno britannico ha lanciato un concorso per ingaggiare la prossima generazione di esperti informatici in grado di fermare gli attacchi cibernetici ai danni del Paese. Studenti e appassionati di tecnologie informatiche, alcuni dei quali con un passato o un presente da hacker, competeranno per una serie di borse di studio e di posti di lavoro in alcune delle migliori istituzioni del Paese.

Fonte TGCOM

Articoli Correlati

Cosa si intende per banda larga secondo gli USA nel 2010

Mentre noi speriamo di avere conenssioni internet che viaggino a qualche megabit (quando va bene) almeno nelle zone cittadine oppure più industrializzate (che comunque rimane un sogno…).. la Federal Communication Commission decide di alzare il limite minimo di quella che può essere definita una connessione a “banda larga”, preparandosi nei prossimi anni ad estendere tale limite a chi ne è attualmente sprovvisto.

Basandosi sugli studi sul comportamento e le aspettative dei netizen, la FCC dice di ritenere necessaria la definizione di uno standard broadband minimo di 4 Megabit in downstream e 1 Megabit in upstream. Il nuovo metro della banda larga statunitense va a sostituire quello precedente risalente al 1999, quando la commissione considerava 200 Kilobit al secondo una velocità sufficiente per applicazioni avanzate come le comunicazioni su VoIP.

Il rapporto lo trovate qui: Rapporto FCC banda larga 2010.

Articoli Correlati

Banda Larga: Novanta milioni di euro per la banda larga dall'Europa

Riporto integralmente dal sito dell’Unione Europea… sperando che un po’ alla volta anche da noi cambi qualcosa e che le promesse di banda larga non siano solo le chiavette o le adsl paventate come banda larghissima…

€90 million available for research in future internet to make Europe’s systems smart and efficient

(20/07/2010) The EU is investing in the future of the Internet to ensure it will be able to support increasing demands from citizens, businesses and governments. The European Commission today made available €90 million under the Future Internet Public-Private Partnership.

“Ultra fast internet holds the key to delivering sustainable economic and social benefits” Commissioner Neelie Kroes

Researchers from all parts of the Information and Communication Technologies (ICT) sector can apply for funding for projects in 2011. This research will focus on innovative internet applications to make infrastructures like health systems, energy grids or traffic management systems ‘smart’.

The €90 million are part of the €300 million from the EU research framework programme (FP7) that will be provided for this purpose over 2011-2013 (see IP/10/966 and MEMO/10/339) – with a further €300 million coming from industry. This complements the Commission’s €200 million yearly ICT support to ongoing research for internet technology. Under the Digital Agenda for Europe (see IP/10/581, MEMO/10/199 and MEMO/10/200 ), the Commission has committed to maintain the pace of yearly increases of the ICT research budget until 2013. The Digital Agenda also invites EU Member States to double annual total public spending on ICT research by 2020 to €11 billion.

Commission Vice-President for the Digital Agenda, Neelie Kroes, said: “Ultra fast internet holds the key to delivering sustainable economic and social benefits. Europe and its businesses should seize the opportunity to develop new technologies and applications that can increase tremendously the economic and social efficiency of processes we use every day.”

Internet data traffic is today growing by 60% every year. We already rely on the Internet to deliver many essential services. In the coming years we will depend on it for delivering a whole range of new services supporting policy objectives in climate change, mobility, energy saving, healthcare, governance etc.

The aim of the Future Internet Public-Private Partnership is to improve key ICT infrastructures of Europe’s economy and society by making them better able to process massive amounts of data coming from different sources. It should also render the Internet more reliable and secure to allow real time information to be processed into real time services.

Under the Future Internet Public-Private Partnership, €90 million of funding is available from the EU for 2011, with a further €210 million in 2012-2013. EU funding for the Future Internet PPP will go to strategic projects that link industry sectors across Europe to leverage advanced internet infrastructure and build innovative services. The call published today for 2011 seeks innovative projects integrating different industries to build on previous achievements and use the strengths of the public sector.

The Future Internet PPP aims to close the gap between research and innovation, and between technology supply and the user demand. To receive financial support, projects have to show commitment to the bigger picture. Phase one looks at integrating the underlying technology and developing use case scenarios; phase two looks at making available the future internet core platform, large scale trials and pilots; and phase three massively broadens the scope to large-scale trials with real applications. SMEs and user-driven innovation are expected to play a key role.

Until now, EU research funding in this field has been split between many different projects. The Future Internet PPP will focus the combined efforts of the European Commission, Member States and industry on a few innovation flagship projects to make Europe a leader in the research and roll-out of future innovative internet technologies needed to ‘smarten up’ infrastructures in areas affecting daily life like health, transport, and energy.

The Future Internet public-private partnership fits into the EU2020 strategy that sets out for a social market economy with a smart, sustainable and inclusive growth. The public-private partnership is part of the Digital Agenda for Europe’s efforts to deliver economic benefits from fast and ultrafast internet and interoperable applications. The PPP aims to support an internet-enabled service economy using so-called ‘cloud computing’ (i.e. computer services delivered over the internet) and a wealth of real world data.

Examples of existing EU smart network research

Smart systems are already being piloted in regions and cities throughout Europe. For example, the city of Santander, together with Telefonica, is establishing “Smart Santander”, a unique city-scale experimental research facility that supports internet applications and services for a smart city. More than 20,000 sensors and objects such as cameras will be connected to the internet for testing new ideas and new services for managing traffic, energy consumption and other services. This project has received €6 million from the EU and an extra €4 million from private investors.

The SmartTouch project in Finland is the EU’s largest project on testing Near Field Communication (NFC) technology, a wireless communication technology which enables data to be exchanged between devices over about a 10 centimeter distance. The project involved partners from different fields: technology and service producers, researchers and organizations setting up first pilots. Two years after the start of the project, the basis of NFC-enabled services has been laid. In addition to the usual payment and ticketing services, SmartTouch partners have also tackled access control, infotainment and entertainment services.

ICiNG, the Innovative Cities of the Next Generation, creates an integrating city that remains sensitive to the needs of its citizens to continuously improve their quality of life. The ICiNG city has a network of environmental sensors and points of interaction for the mobile devices of its citizens which leads to a reduction in response time of the public services.

The Commission wants governments and industry to work together so that European research focuses further on key internet technologies and their fast application to daily life. The Commission, as shown in the examples, is already funding research that is making the internet itself smarter, with €650 million invested in nearly 100 European projects under its ICT research programme for 2007-2013

Articoli Correlati

Nuovo aggiornamento di sicurezza per mozilla Firefox

A tempo di record un nuovo aggiornamento di sicurezza per mozilla Firefox. La nuova versione, 3.6.8 viene rilasciata  a causa di un bug che rendeva il browser instabile in particolari combinazioni di siti Web e plugin. Qui le note tecniche del rilascio.

Articoli Correlati

Sql server 2008 express non ascolta sulla porta 1433

Non siamo esperti di sql server ma lo utiliziamo abbastanza frequentemente per i nostri progetti.

L’altro giorno un cliente ci chiede di fare dei test con un noto programma open source di content management chiedendoci pero’ di utilizzare, al posto dei classici Mysql oppure Postgresql, il server MSSQL. Vabbe’, che ci vuole?

Installiamo in una macchina Windows2008 il succitato pacchetto express di Microsoft, configuriamo accessi e database, applichiamo le patch varie configuriamo il server per permettere le connessioni via TCP/IP, come sempre via pannello di controllo di SQL server. Facile no?  Da un’altra macchina collegata in rete (ma non nel dominio), fiduciosi, cerchiamo di connetterci al server e… Sorpresa!!!! non ci connettiamo!!!! Ma come? Lanciamo una scansione e poi un telnet sulla porta 1433 e nulla… La porta non sembra aperta.

Impossibile!!!!

Proviamo a fare il browser dei database da una macchina collegata in dominio e… tutto funziona!!!! Riproviamo dall’altra macchina e ancora nulla!!!!

A questo punto cominciamo una ricerca su internet. Una miriade di siti che dicono di fare come abbiamo fatto e che tutto DEVE funzionare. Ma non funziona.  Se non funziona dicono di reinstallare tutto. No, questa non ci sembra una ipotesi percorribile. Proviamo a fare la stessa cosa sul nostro portatile di sviluppo e…. stessa situazione (stavolta il sistema operativo è windows 7 professional ma la sostanza non cambia).

Una mezza idea era quella di abilitare esplicitamente la connessione alla porta 1433 su tutte le schede di rete configurate ma abbiamo preferito continuare la nostra ricerca su internet e ci siamo imbattuti in questo articolo. Sembra esattamente il nostro caso.

Applichiamo quello che dicono, all’esclusione della modifica del registro e…. ora tutto funziona.

Alla faccia di chi crede ancora che l’informatica sia sempre più user friendly… Un giorno perso per connettere in rete un server sql server 2008…..

Articoli Correlati

USN-930-5: ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update

Description: 
===========================================================
Ubuntu Security Notice USN-930-5 July 23, 2010
ant, apturl, epiphany-browser, gluezilla, gnome-python-extras,
liferea, mozvoikko, openjdk-6, packagekit, ubufox, webfav,
yelp update
https://launchpad.net/bugs/599954
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS
Ubuntu 9.04
Ubuntu 9.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:

Ubuntu 9.04:
ant 1.7.1-0ubuntu2.2
apturl 0.3.3ubuntu1.2
epiphany-browser 2.26.1-0ubuntu1.9.04.1
icedtea6-plugin 6b18-1.8-4ubuntu3~9.04.2
libgluezilla 2.0-1ubuntu1.9.04.1
liferea 1.4.26-0ubuntu1.9.04.1
mozilla-packagekit 0.3.14-0ubuntu5.9.04.1
mozvoikko 0.9.5-1ubuntu2.9.04.1
python-gnome2-extras 2.19.1-0ubuntu14.9.04.1
ubufox 0.9~rc2-0ubuntu0.9.04.2
webfav 1.11-0ubuntu1.9.04.1
yelp 2.25.1-0ubuntu5.9.04.1

Ubuntu 9.10:
ant 1.7.1-4ubuntu0.2
icedtea6-plugin 6b18-1.8-4ubuntu3~9.10.2
mozvoikko 1.0-1ubuntu3.9.10.1
python-gtkmozembed 2.25.3-3ubuntu1.9.10.1
ubufox 0.9~rc2-0ubuntu0.9.10.1
webfav 1.16-0ubuntu1.9.10.1
yelp 2.28.0-0ubuntu2.9.10.1

After a standard system upgrade you need to restart Firefox and any
applications that use Xulrunner to effect the necessary changes.

Details follow:

USN-930-4 fixed vulnerabilities in Firefox and Xulrunner on Ubuntu 9.04 and
9.10. This update provides updated packages for use with Firefox 3.6 and
Xulrunner 1.9.2.

Original advisory details:

If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)

Several flaws were discovered in the browser engine of Firefox. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,
CVE-2010-1202, CVE-2010-1203)

A flaw was discovered in the way plugin instances interacted. An attacker
could potentially exploit this and use one plugin to access freed memory from a
second plugin to execute arbitrary code with the privileges of the user
invoking the program. (CVE-2010-1198)

An integer overflow was discovered in Firefox. If a user were tricked into
viewing a malicious site, an attacker could overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1196)

Martin Barbella discovered an integer overflow in an XSLT node sorting
routine. An attacker could exploit this to overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1199)

Michal Zalewski discovered that the focus behavior of Firefox could be
subverted. If a user were tricked into viewing a malicious site, a remote
attacker could use this to capture keystrokes. (CVE-2010-1125)

Ilja van Sprundel discovered that the ‘Content-Disposition: attachment’
HTTP header was ignored when ‘Content-Type: multipart’ was also present.
Under certain circumstances, this could potentially lead to cross-site
scripting attacks. (CVE-2010-1197)

Amit Klein discovered that Firefox did not seed its random number generator
often enough. An attacker could exploit this to identify and track users
across different web sites. (CVE-2008-5913)

Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious site, a remote attacker could use
this to crash the browser or possibly run arbitrary code as the user
invoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,
CVE-2010-1212)

An integer overflow was discovered in how Firefox processed plugin
parameters. An attacker could exploit this to crash the browser or possibly
run arbitrary code as the user invoking the program. (CVE-2010-1214)

A flaw was discovered in the Firefox JavaScript engine. If a user were
tricked into viewing a malicious site, a remote attacker code execute
arbitrary JavaScript with chrome privileges. (CVE-2010-1215)

An integer overflow was discovered in how Firefox processed CSS values. An
attacker could exploit this to crash the browser or possibly run arbitrary
code as the user invoking the program. (CVE-2010-2752)

An integer overflow was discovered in how Firefox interpreted the XUL
element. If a user were tricked into viewing a malicious site, a
remote attacker could use this to crash the browser or possibly run
arbitrary code as the user invoking the program. (CVE-2010-2753)

Aki Helin discovered that libpng did not properly handle certain malformed
PNG images. If a user were tricked into opening a crafted PNG file, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-1205)

Yosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin
check in Firefox could be bypassed by utilizing the importScripts Web
Worker method. If a user were tricked into viewing a malicious website, an
attacker could exploit this to read data from other domains.
(CVE-2010-1213, CVE-2010-1207)

O. Andersen that Firefox did not properly map undefined positions within
certain 8 bit encodings. An attacker could utilize this to perform
cross-site scripting attacks. (CVE-2010-1210)

Michal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no
content) code. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2010-1206)

Jordi Chancel discovered that Firefox did not properly handle when a server
responds to an HTTPS request with plaintext and then processes JavaScript
history events. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2010-2751)

Chris Evans discovered that Firefox did not properly process improper CSS
selectors. If a user were tricked into viewing a malicious website, an
attacker could exploit this to read data from other domains.
(CVE-2010-0654)

Soroush Dalili discovered that Firefox did not properly handle script error
output. An attacker could use this to access URL parameters from other
domains. (CVE-2010-2754)

Articoli Correlati

  • No Related Posts

USN-957-1: Firefox and Xulrunner vulnerabilities

Referenced CVEs: 
CVE-2010-0654, CVE-2010-1205, CVE-2010-1206, CVE-2010-1207, CVE-2010-1208, CVE-2010-1209, CVE-2010-1210, CVE-2010-1211, CVE-2010-1212, CVE-2010-1213, CVE-2010-1214, CVE-2010-1215, CVE-2010-2751, CVE-2010-2752, CVE-2010-2753, CVE-2010-2754

Description: 
===========================================================
Ubuntu Security Notice USN-957-1 July 23, 2010
firefox, firefox-3.0, xulrunner-1.9.2 vulnerabilities
CVE-2010-0654, CVE-2010-1205, CVE-2010-1206, CVE-2010-1207,
CVE-2010-1208, CVE-2010-1209, CVE-2010-1210, CVE-2010-1211,
CVE-2010-1212, CVE-2010-1213, CVE-2010-1214, CVE-2010-1215,
CVE-2010-2751, CVE-2010-2752, CVE-2010-2753, CVE-2010-2754
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS
Ubuntu 10.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
firefox-3.0 3.6.7+build2+nobinonly-0ubuntu0.8.04.1
xulrunner-1.9.2 1.9.2.7+build2+nobinonly-0ubuntu0.8.04.2

Ubuntu 10.04 LTS:
abrowser 3.6.7+build2+nobinonly-0ubuntu0.10.04.1
firefox 3.6.7+build2+nobinonly-0ubuntu0.10.04.1
xulrunner-1.9.2 1.9.2.7+build2+nobinonly-0ubuntu0.10.04.1

After a standard system update you need to restart Firefox to make all the
necessary changes.

Details follow:

Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious site, a remote attacker could use
this to crash the browser or possibly run arbitrary code as the user
invoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,
CVE-2010-1212)

An integer overflow was discovered in how Firefox processed plugin
parameters. An attacker could exploit this to crash the browser or possibly
run arbitrary code as the user invoking the program. (CVE-2010-1214)

A flaw was discovered in the Firefox JavaScript engine. If a user were
tricked into viewing a malicious site, a remote attacker code execute
arbitrary JavaScript with chrome privileges. (CVE-2010-1215)

An integer overflow was discovered in how Firefox processed CSS values. An
attacker could exploit this to crash the browser or possibly run arbitrary
code as the user invoking the program. (CVE-2010-2752)

An integer overflow was discovered in how Firefox interpreted the XUL
element. If a user were tricked into viewing a malicious site, a
remote attacker could use this to crash the browser or possibly run
arbitrary code as the user invoking the program. (CVE-2010-2753)

Aki Helin discovered that libpng did not properly handle certain malformed
PNG images. If a user were tricked into opening a crafted PNG file, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-1205)

Yosuke Hasegawa and Vladimir Vukicevic discovered that the same-origin
check in Firefox could be bypassed by utilizing the importScripts Web
Worker method. If a user were tricked into viewing a malicious website, an
attacker could exploit this to read data from other domains.
(CVE-2010-1213, CVE-2010-1207)

O. Andersen that Firefox did not properly map undefined positions within
certain 8 bit encodings. An attacker could utilize this to perform
cross-site scripting attacks. (CVE-2010-1210)

Michal Zalewski discovered flaws in how Firefox processed the HTTP 204 (no
content) code. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2010-1206)

Jordi Chancel discovered that Firefox did not properly handle when a server
responds to an HTTPS request with plaintext and then processes JavaScript
history events. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2010-2751)

Chris Evans discovered that Firefox did not properly process improper CSS
selectors. If a user were tricked into viewing a malicious website, an
attacker could exploit this to read data from other domains.
(CVE-2010-0654)

Soroush Dalili discovered that Firefox did not properly handle script error
output. An attacker could use this to access URL parameters from other
domains. (CVE-2010-2754)

Articoli Correlati

  • No Related Posts