11.30.07 - 10:28pm
Jeff Jones, a director of security strategy at Microsoft published a report today about counting bugs. I blogged a few months ago about why I think counting bugs is less than useful:
Since all software has bugs, it’s more important to consider how long it takes to get a fix out when a security [...]
Category: Firefox, Musings, Press, Security | | 14 Comments »
11.16.07 - 04:52pm
Issue
jar: protocol is not restricted to java archives and will open any zip format file. An attacker can use this to evade filtering on sites that allow users to upload content and use this initiate a cross site scripting attack.
Impact
Firefox supports the Java Archive URI scheme that allows the addressing of the contents [...]
Category: Firefox, Security, Vulnerabilities | | 1 Comment »
09.18.07 - 03:09pm
Firefox 2.0.0.7 was released this afternoon to patch the QuickTime issue described here. This will protect Firefox users from the public critical security vulnerability until a patch is available from Apple. I would like to personally thank the individuals at Apple who worked with us and the engineers at Mozilla that work so [...]
Category: Announcements, Firefox, Security, Security Updates, Vulnerabilities | | Be the First to Comment »
07.30.07 - 09:11pm
We’ve just released Firefox 2.0.0.6 which contains a security patch to mitigate the issue described here. The patch enables percent-encoding for spaces and double-quotes in URIs handed off to external programs. This reduces the risk of malicious data being passed through Firefox to another application that may then trigger unexpected and potentially dangerous [...]
Category: Announcements, Firefox, Security Updates, Vulnerabilities | | 1 Comment »
07.25.07 - 02:15pm
Issue
We are currently investigating an issue on Windows XP, where some urls for “web” protocols that contain %00 launch the wrong handler and appear to be able to launch local programs, with limited argument passing.
Impact
The impact to users is unknown at this point in time. We are working to verify this and in the [...]
Category: Firefox, Security, Vulnerabilities | | 8 Comments »
07.18.07 - 11:49am
Firefox 2.0.0.5 is now available and there is a fix for the URL protocol handling issue described here. We warned that other Windows applications may be vulnerable to this Internet Explorer issue, and on Sunday Nate Mcfeters, Billy Rios, and Raghav Dube posted a proof of concept that demonstrates the same attack through Internet [...]
Category: Announcements, Firefox, Security, Security Updates, Vulnerabilities | | 21 Comments »
07.10.07 - 02:04pm
Today security firm Secunia released an advisory on a security issue found (apparently) simultaneously and independently by Greg MacManus and Billy Rios based on a previously reported issue in Safari found by Thor Larholm.
Any Windows application that calls a registered URL protocol without escaping quotes may be used to pass unexpected and potentially dangerous data [...]
Category: Firefox, Security, Security Updates, Vulnerabilities | | 23 Comments »
06.18.07 - 03:35pm
Since all software has bugs, it’s more important to consider how long it takes to get a fix out when a security issue is discovered than it is to count bugs. Number of vulnerabilities identified is a function of how many bugs are present, but is probably more influenced by things like who is [...]
Category: Firefox, Musings, Press, Security, Security Updates | | 7 Comments »