10.19.09 - 04:17pm
Mike Shaver has posted an update on the situation surrounding our blocking of the .Net Framework Assistant and WPF plugin. In it, he discusses the current state of affairs, the series of events that got us to this point, as well as the steps we, and Microsoft, are taking to get the situation resolved.
Category: Announcements, Firefox, Security | | 20 Comments »
10.13.09 - 07:35pm
A little over a month ago, I talked about a project we had started to inform users when their plugins were out of date. This is a really important project for us, because old versions of plugins can cause crashes and other stability problems, and can also be a major security risk. In the first [...]
Category: Announcements, Firefox, Security | | 16 Comments »
09.30.09 - 02:42pm
As we mentioned earlier we’ve been working for the past few months on turning the Content Security Policy specification into working Firefox code. (You’ll remember that CSP is a framework to protect websites from XSS and related attacks). We are happy to report that the work is nearly finished, and we have some preview builds [...]
Category: Firefox, Security | | 11 Comments »
09.04.09 - 02:28pm
Starting with the upcoming releases of Firefox 3.5.3 and Firefox 3.0.14, Mozilla will warn users if their version of the popular Adobe Flash Player plugin is out of date. Old versions of plugins can cause crashes and other stability problems, and can also be a significant security risk. For now our focus is on the [...]
Category: Firefox, Security | | 36 Comments »
08.25.09 - 03:29pm
The best way for users to stay safe online is to use an updated browser. While most Firefox users get updated quickly, some fall behind for various reasons. We’re looking for ways to increase uptake while still preserving user choice. Ken Kovash and Eric Hergenrader surveyed users who have update-checking enabled but repeatedly chose not [...]
Category: Firefox, Security Updates | | 32 Comments »
07.28.09 - 03:40pm
Issue The URL in the address bar can be spoofed when a new window or tab is opened by a malicious web page. Impact to users If a user visits a page hosting this malicious code, a new window or tab can be opened with a faked URL. There is no way of determining if [...]
Category: Firefox, Security, Vulnerabilities | | 15 Comments »
07.27.09 - 05:17pm
Computers are increasingly mobile and, to serve them, more and more public spaces (cafes, airports, libraries, etc.) offer their customers WiFi access. When a web browser on such a network requests a resource, it is implicitly trusting the hotspot not to interfere with the communication. A malicious computer hooked up to the network could alter [...]
Category: Firefox, Security | Tags: Firefox, forcetls, https, Security | 18 Comments »
07.20.09 - 05:36pm
This Tuesday (2009-07-21), I’m organizing a crash bug triage day where anyone interested can help us classify the swamp of open crash bugs. Join us in #bugday on irc.mozilla.org if you’d like to help. Crashes and security Some Firefox crash bugs are severe security bugs. A crash bug is likely to be exploitable if it [...]
Category: Firefox, Security | | 6 Comments »
07.19.09 - 02:44pm
In the last few days, there have been several reports (including one via SANS) of a bug in Firefox related to handling of certain very long Unicode strings. While these strings can result in crashes of some versions of Firefox, the reports by press and various security agencies have incorrectly indicated that this is an [...]
Category: Firefox, Security, Vulnerabilities | | 16 Comments »
07.14.09 - 10:15am
Issue A bug discovered last week in Firefox 3.5′s Just-in-time (JIT) JavaScript compiler was disclosed publicly yesterday. It is a critical vulnerability that can be used to execute malicious code. Impact The vulnerability can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code. The vulnerability [...]
Category: Firefox, Security, Vulnerabilities | | 80 Comments »