On TV.com: Super Bowl Fun: DAVE + JAY + OPRAH
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Sep 9, 2005 10:53:00 AM

A new, unpatched flaw that affects all versions of Firefox could let attackers surreptitiously run malicious code on users' PCs, a security researcher has warned.

The problem lies in the way Firefox handles Web links that are overly long and contain dashes, security researcher Tom Ferris said in an interview via instant messaging late Thursday.

He posted an advisory and a proof of concept to the Full Disclosure security mailing list and to his Security Protocols Web site.

The security vulnerability is a buffer overflow flaw that "allows for an attacker to remotely execute arbitrary code" on a vulnerable PC, Ferris said. An attacker could host a Web site containing the malicious code to exploit the flaw, he said. Though his proof of concept only crashes Firefox, Ferris claims he has been able to tweak it to run code.

Buffer overflows are a commonly exploited security problem. They occur when a program allows data to be written beyond the allocated end of a buffer in memory. A computer can be made to execute potentially malicious code by feeding in extra data that is designed to flood the buffer.

Ferris reported the bug to the Mozilla Foundation on Sunday, intending to go through the organization's bug-reporting process, he said. However, in an example of the uneasy alliance between security researchers and software makers, he decided to publicly disclose the flaw after a run-in with Mozilla staff, he said.

Mozilla, which coordinates the development of Firefox and distributes the software, on Friday confirmed the bug but said the scope of the flaw is still under investigation. The organization said it received the bug report on Tuesday, not Sunday.

"We believe there is a buffer overflow issue," said Mike Schroepfer, director of engineering at Mozilla. "We are still determining whether it is exploitable in an attack."

Users are currently not at risk because there are no known attacks that take advantage of the flaw, Schroepfer said. Mozilla is working on a fix that will be released with an upcoming version of Firefox, he said.

Mozilla is unhappy with the disclosure of the flaw. "We'd like to make sure that by the time something goes public, we have a solution for the users," Schroepfer said.

Since the debut of Firefox 1.0 in November, usage of the open-source browser has grown. Security has been a main selling point for Firefox over Microsoft's Internet Explorer, which has begun to see its market share dip slightly--for the first time in years.

However, Firefox has had its own security woes. Several serious holes in the browser have been plugged since its official release, and experts have said that safe Web browsers don't exist.

The public bug disclosure comes just as Mozilla released the first beta of Firefox 1.5. The final release of the next Firefox update, which includes security enhancements, is due by year's end, according to the Firefox road map.

Ferris has found bugs in Microsoft software before, including a yet-unpatched flaw in Internet Explorer that Microsoft still has under investigation.

Earlier this month Microsoft credited Ferris with reporting a bug in a Windows feature called Remote Desktop Protocol that could allow an attacker to remotely restart Windows systems.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 166 Talkback(s)
Do firewalls like Zone Alarm stop hackers using IE or Firefox exploits ?
I may have missed this, but DO firewalls, such as Zone alarm,Norton Internet security pro, etc, prevent hackers from getting into your computer through browser flaws ? All I ever see reported is the f... (Read the rest)
Posted by: racintazz@... Posted on: 12/31/05 You are currently: a Guest | | Terms of Use
"After a run-in with Mozilla staff..."  Real World | 09/09/05
Understandable  ejhonda | 09/09/05
Fine  Real World | 09/09/05
That's how we feel  wjvann@... | 09/09/05
A glory houd is a glory hound  Real World | 09/09/05
Justifiy...  D-Ram | 09/09/05
This is the type of person we need?  Real World | 09/09/05
Generally accepted 30 days??  Too Old For IT | 09/09/05
Based on conversations like  Real World | 09/09/05
I would be willing to bet FF fixes it befor MS  IceTheNet@... | 09/09/05
Yes  nucrash | 09/09/05
MS, Mozilla, Apple, whomever  Real World | 09/09/05
Took their time?  rpmyers1 | 09/09/05
Took their time?  flatliner | 09/09/05
And Then...And Then  Santelli | 09/09/05
Here's the part I don't understand  Real World | 09/10/05
mjb FYI  D-Ram | 09/13/05
This is the type of person we need?  lithic | 09/09/05
FireFox Patch  Bobby Joe Reed | 09/10/05
FF  Bobby Joe Reed | 09/10/05
Firefox talk?  ab@... | 09/09/05
it might...  kiwi704 | 09/10/05
Understandable Plus  pjones | 09/09/05
Oh really???  shango1052 | 09/09/05
yes really  D-Ram | 09/13/05
Exactly...  PeregrineFalcon | 09/09/05
Hey bro...  D-Ram | 09/09/05
Browser in Development  Too Old For IT | 09/09/05
I wish!  PeregrineFalcon | 09/09/05
Sorry ...  msdead | 09/09/05
Security layers needed  uno@... | 09/10/05
I am a Firefox user...  msdead | 09/09/05
I disagree  Real World | 09/09/05
Hmmm...  msdead | 09/09/05
4 days  rpmyers1 | 09/09/05
Incorrect analogy  cdgoldin | 09/09/05
I disagree plus  pjones | 09/09/05
only YOU can prevent buffer overflows  ouvrez | 09/09/05
The current family of Intel processors ...  ShadeTree | 09/09/05
memory managers  Anti_Zealot | 09/09/05
No,  PeregrineFalcon | 09/09/05
How does hardware know the buffer size?  woot! | 09/09/05
...  PeregrineFalcon | 09/09/05
Buffer the Vampire Slayer  IceTheNet@... | 09/09/05
I give up,  PeregrineFalcon | 09/09/05
There's no excuse  woot! | 09/09/05
flaw in Mozilla  asmirick@... | 09/09/05
but yet..  D-Ram | 09/13/05
he already went public when he posted the bug!  pablito@... | 09/09/05
FYI,  PeregrineFalcon | 09/09/05
Not so  uno@... | 09/10/05
Problem fixed in less than 24 hrs (a week since it was notified of the bug)  wackoae | 09/10/05
This affects to Netscape 8 too  MickJ | 09/09/05
Can anyone else confirm the flaw?  toomuchgreeatea@... | 09/09/05
Never mind (NT)  toomuchgreeatea@... | 09/09/05
Let me make a correction  toomuchgreeatea@... | 09/09/05
Hmm?  PeregrineFalcon | 09/09/05
Works just fine  IT Scion | 09/09/05
Crashed mine just fine!  crash89 | 09/09/05
Won't work...  PeregrineFalcon | 09/09/05
Work around confirmed. Thanks (NT)  toomuchgreeatea@... | 09/09/05
Yup that did the trick...thnx(nt)  IT Scion | 09/09/05
DOESN'T CRASH MY BROWSER!  Valis Keogh | 09/09/05
I can't. And I'm running 1.0.3  hawkeyeaz1 | 09/09/05
Doesn't work here...  figgle | 09/09/05
I'm wondering...  PeregrineFalcon | 09/09/05
It crashed mine but  IT Scion | 09/09/05
I know. Isn't that weird?  toomuchgreeatea@... | 09/09/05
Not sure but  IT Scion | 09/09/05
mine never crashes...  doh123 | 09/09/05
Ok, now it crashed...  figgle | 09/09/05
Crashed Using 1.0.6 Win XP SP1 (nt)  tbbrickster_z | 09/09/05
Anyone else has any luck crashing the browser?  bka1959 | 09/09/05
So Far everything but Opera I crashed  nucrash | 09/09/05
I can.  Immanuel Tranz-Mischen | 09/10/05
No crashing here...  Linux Guy 1000 | 09/11/05
Another M$ Bug!  regloff@... | 09/09/05
See my above post  crash89 | 09/09/05
flaws in published web material  jimmy5 | 09/09/05
Doesn't crash my browser...  figgle | 09/09/05
Doesn't Crash My Browser  Too Old For IT | 09/09/05
Clueless...  figgle | 09/09/05
It works  IT Scion | 09/09/05
doesnt exactly crash mine either, but...  doh123 | 09/09/05
dash dash address  trm1945 | 09/09/05
Unpatched Firefox flaw may expose users  Loverock Davidson | 09/09/05
Just kidding  Loverock Davidson | 09/09/05
The story says he didn't prove it to Mozilla  Feamster Business Services | 09/09/05
Is there an editor in the audience?  dhopp@... | 09/09/05
I guess there's no profit in moderation  Feamster Business Services | 09/09/05
editor in the audience...  clifflee | 09/09/05
Cheap shot!  cdgoldin | 09/09/05
What?  Immanuel Tranz-Mischen | 09/10/05
Bene, cum Latine nescias...  cdgoldin | 11/08/05
The latin word ZDnet censored is c_u_m, ...  cdgoldin | 11/08/05
reformat  solocanoejake@... | 09/09/05
What? Troubleshoot much?  nikoli | 09/09/05
winsock?  Real World | 09/09/05
Winsock on WinXP Pre SP1  Too Old For IT | 09/09/05
Isn't it funny that...  net2dave | 09/09/05
PEOPLE......OPERA IS THE KEY.FOR NOW.  Someoneinthecrowdhere | 09/09/05
Who cares? It doesn't matter to the government.  msdead | 09/09/05
Since this isn't IE  node357 | 09/09/05
Good Point  Jovan66102 | 09/09/05
Holds little water....  IT Scion | 09/09/05
Prove It  node357 | 09/09/05
Time it.  dbrimlow | 09/09/05
Do you honestly think  IT Scion | 09/09/05
Calrification  IT Scion | 09/09/05
What Makes Secunia the Gold Standard Anyway? (nt)  PMC-CON | 09/10/05
For .00001% of the User Population  PMC-CON | 09/10/05
wow what a novel idea..  D-Ram | 09/13/05
More eyes  michael_t | 09/11/05
Ya just don't get it, do ya?  Motu | 09/09/05
What platform do you write for?  IT Scion | 09/09/05
re: What platform do you write for?  Motu | 09/09/05
So give firefox a shot  rpmyers1 | 09/09/05
re: So give firefox a shot  Motu | 09/12/05
Not your grandfather's IBM!  cdgoldin | 09/09/05
What is storage protect?  rpmyers1 | 09/09/05
Listen me lad, and ye shall hear...  cdgoldin | 09/09/05
Take a course on operating systems...  PeregrineFalcon | 09/09/05
Thank you, Mr. Peregrine (Falcon)  cdgoldin | 11/08/05
Re: Granddad's IBM  BXLE | 09/09/05
386-40  cdgoldin | 09/09/05
re: Not your grandfather's IBM!  Motu | 09/12/05
IE is still crap  Stegosaurus Cowboy | 09/09/05
Don't let the fact confuse you!  cdgoldin | 09/09/05
Warez and Porn?  rpmyers1 | 09/09/05
re: "Don't Let the Fact Confuse You!"  Stegosaurus Cowboy | 09/09/05
kudos to both of you for an argument sans childishness! *pat on back* (nt)  Valis Keogh | 09/09/05
Oops?  cdgoldin | 09/09/05
The fact that if we let security aside  michael_t | 09/11/05
Ahhh the troll of the day!  IT Scion | 09/09/05
Another poorly done "slight of hand" post here  John Zern | 09/09/05
Don't you mean "sleight of hand"?  Stegosaurus Cowboy | 10/12/05
Says It All  PMC-CON | 09/10/05
LMAO  D-Ram | 09/13/05
Confirmed work around posted  toomuchgreeatea@... | 09/09/05
Hard to understand...  HerbieHightower | 09/09/05
Easy to understand  Loverock Davidson | 09/09/05
Outbreaks affect more than just those who got infected  Michael Kelly | 09/09/05
I invite you  IT Scion | 09/09/05
I certainly hope so  Michael Kelly | 09/09/05
2 Days Vs. 2 Weeks  MildlyAmuzed | 09/09/05
How stupid  victor@... | 09/10/05
Another Interpretation: Fear of MS  PMC-CON | 09/10/05
if you had read...  D-Ram | 09/13/05
Has anyone already exploited this ? How? nt  michael_t | 09/09/05
Easy enough to fix. What's the big deal ?  Budone | 09/09/05
Why Doesn't Mozilla Support Page Link?  PMC-CON | 09/10/05
Oh, There It Is ... on the bottom, next  PMC-CON | 09/10/05
Where's George Ou when you need him?  LibrarianDude | 09/09/05
Not to worry  george_ou | 09/14/05
Scariest of ALL  walterreads@... | 09/10/05
Commendation presented  D-Ram | 09/13/05
The flaw no one could find!  An_Axe_to_Grind | 09/10/05
The Cox watch!  An_Axe_to_Grind | 09/10/05
Must be a different guy.  Immanuel Tranz-Mischen | 09/10/05
Firefox is Wonderful!!! Well, at least it used to be.  iom88@... | 09/11/05
Fix is here and simple to apply.  michael_t | 09/11/05
Wot No Reboot?  mischief_z | 09/12/05
Buffer overflows  Roger Ramjet | 09/12/05
It's called .NET Managed Code  mischief_z | 09/12/05
Better Idea  PeregrineFalcon | 09/12/05
Do firewalls like Zone Alarm stop hackers using IE or Firefox exploits ?  racintazz@... | 12/31/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here