Author Topic: New vulnerabilities hit Firefox and Internet Explorer  (Read 877 times)

Offline zuoom

  • Advisor
  • Super Gear
  • *****
  • Posts: 21562
    • CSG - CelicaSG.org
New vulnerabilities hit Firefox and Internet Explorer
« on: June 05, 2007, 09:57:10 AM »
Quote
Security researcher Michal Zalewski has published four new vulnerabilities to the Full Disclosure mailing list for Microsoft Internet Explorer and Mozilla Firefox. There are no patches yet available from either vendor. The most serious is MSIE page update race condition, where users navigating with JavaScript from one page to another page with the same domain experience a window of opportunity for attackers to concurrently execute JavaScript to perform actions with the permissions of the previous page.

The next most severe is Firefox Cross-site IFRAME hijacking where an attack against about:blank frames could allow malicious code execution. Zalewski also published two medium-threat vulnerabilities, one each for Firefox and Internet Explorer. Firefox file prompt delay bypass allows an "attacker to download or run files without user's knowledge or consent." And, finally, Internet Explorer 6 URL bar spoofing is a URL spoofing vulnerability. This last vulnerability does not affect Internet Explorer 7.


Source : download.com

First read on : Vrforums

Offline Vorsprung durch Technik

  • Advisor
  • Super Gear
  • *****
  • Posts: 6131
  • Do it, did that, done with. :P
    • CelicaSG
RE: New vulnerabilities hit Firefox and Internet Explorer
« Reply #1 on: June 05, 2007, 12:30:29 PM »
patches are out for firefox... not sure about internet explorer

Sync your files online and across computers with @Dropbox. 2GB account is free!

Offline zuoom

  • Advisor
  • Super Gear
  • *****
  • Posts: 21562
    • CSG - CelicaSG.org
RE: New vulnerabilities hit Firefox and Internet Explorer
« Reply #2 on: June 06, 2007, 12:00:05 PM »
ya. 2.0.0.4

"strongly recommended to download and install" .P

Offline Vorsprung durch Technik

  • Advisor
  • Super Gear
  • *****
  • Posts: 6131
  • Do it, did that, done with. :P
    • CelicaSG
RE: New vulnerabilities hit Firefox and Internet Explorer
« Reply #3 on: June 07, 2007, 04:12:47 AM »
if you are onto firefox, and have install many add-ons, you might like this particular tool

Sync your files online and across computers with @Dropbox. 2GB account is free!