Clan Adverts

PHP Web Host - Quality Web Hosting For All PHP Applications

  FireFox 2.0.0.6

Posted on Tuesday, July 31, 2007 @ 17:35 by floppy
FireFox 2.0.0.6 updates

MFSA 2007-27 Unescaped URIs passed to external programs

Mozilla Foundation Security Advisory 2007-27

Title: Unescaped URIs passed to external programs
Impact: Critical
Announced: July 30, 2007
Reporter: Jesper Johansson
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 2.0.0.6
  Thunderbird 2.0.0.6
  Thunderbird 1.5.0.13
  SeaMonkey 1.1.4

Description

Jesper Johansson pointed out that Mozilla did not percent-encode spaces and double-quotes in URIs handed off to external programs for handling, which can cause the receiving program to mistakenly interpret a single URI as multiple arguments. The danger depends on the arguments supported by the specific receiving program, though at the very least we know Firefox (and Thunderbird) 2.0.0.4 and older could be used to run arbitrary script (see MFSA 2007-23). The vast majority of programs do not have dangerous arguments, though many could still be made to do something unexpected.

A similar issue with URIs passed to external handlers was reported by Billy Rios and Nate McFeters. When running Firefox on Windows XP with IE7 installed, URIs for certain common protocols (such as mailto:) that contain a %00 do not launch the protocol handler registered for that scheme but instead launch a file handling program based on the file extension at the end of the URI. Coupled with the issue reported by Jesper Johansson this appears to allow execution of any program installed at a known location and limited argument passing that might be enough to exploit a system. Further investigation by Secunia showed that a % not followed by a valid two-digit hexadecimal number also triggered the problem for the affected protocols. The Firefox and Thunderbird 2.0.0.6 releases contain fixes that prevent the original demonstrations of this variant, but it is still possible to launch a filetype handler based on extension rather than the registered protocol handler. A way to exploit a common handler with a single unexpected URI as an argument may yet be found. Since this handling is a property of the Windows Shell API this variant appears to affect other internet-enabled applications that pass these URIs to the Windows Shell.

Workaround

By default Firefox will ask before launching external protocol handlers, and these prompts should be denied from sites that are not trustworthy, especially if the requested URL contains spaces and double-quote (") characters. An exception is made for mail-related protocols in Firefox, they do not prompt by default. If the default mail handler is Thunderbird 2.0.0.5 or later there will not be a problem, but if another program or older version of Thunderbird is the default handler then mail URIs can be made to prompt as well. (Similarly, in Thunderbird browser protocols like http: and ftp: do not prompt but instead launch the default browser.) To make mail-related links prompt in Firefox before launching external programs:
  • Enter about:config in the location bar
  • Enter warn-external in the Filter: box
  • Double-click to set the mailto, news, nntp, and snews lines to true

MFSA 2007-26 Privilege escalation through chrome-loaded about:blank windows

Mozilla Foundation Security Advisory 2007-26

Title: Privilege escalation through chrome-loaded about:blank windows
Impact: Moderate
Announced: July 30, 2007
Reporter: moz_bug_r_a4
Products: Firefox 2.0.0.5, Thunderbird 2.0.0.5, SeaMonkey 1.1.3

Fixed in: Firefox 2.0.0.6
  Thunderbird 2.0.0.6
  Thunderbird 1.5.0.13
  SeaMonkey 1.1.4

Description

Mozilla researcher moz_bug_r_a4 reported that a flaw was introduced by the fix for MFSA 2007-20 that could enable privilege escalation attacks against addons that create "about:blank" windows and populate them in certain ways (including implicit "about:blank" document creation through data: or javascript: URLs in a new window).

Workaround

Any workaround would depend on the addon in question. One addon known to be affected was the Web Developer Toolbar, which was safe in its default configuration but potentially vulnerable to malicious web content if informational windows were opened as separate windows instead of tabs. The workaround for this, then, is to switch back to the default setting.

Other affected addons might not have a workaround other than to upgrade to a fixed version of Firefox.

Download The latest version of FireFox

Quick Searches

Related Articles

The comments below belong to their respectful owners, Clan Themes can not be held responsible for any of the below comments. You also read the below comments at your own choice.

NEOXID

NEOXID writes 
This is very good web browser! I like it so much...

Wednesday, August 01, 2007 @ 04:02

floppy

floppy writes 
Firefox is the best. No doubting that. You can find read some other firefox news here. Good extensions etc.

Wednesday, August 01, 2007 @ 09:12

gtmaniak

gtmaniak writes 
I don't know what I would do without Firefox. M$ tried with IE7, but only got half way there.

Wednesday, August 08, 2007 @ 19:25

uchiraka

uchiraka writes 
its certainly the bestttt

Saturday, August 11, 2007 @ 05:19

MuadDib

MuadDib writes 
I just love Mozilla. I am usign Mozilla on the Linux and Windows. She is so CooL
My favourite plugin is FireFTP

Tuesday, August 14, 2007 @ 15:52

underoath

underoath writes 
Firefox for the win!

Sunday, August 26, 2007 @ 03:49

Comments Closed for this Article!
Comments are always closed 1 month after the article has been published.
 

  Farcry 2 News

  Article Rating

Average Score: 3.8
Votes: 10


Please take a second and vote for this article:

Excellent
Very Good
Good
Regular
Bad