Security [CENTRAL] Forum - SCforum.info
05. February 2012., 03:21:03 *
Welcome, Guest. Please login or register.

Login with username, password and session length
Help Niamh

Custom Search
News: Zemana AntiLogger - 50 licenses Giveaway !!!
 
  Home Help Chess Links Login Register   *

SCforum.info





Members
Total Members: 11367
Latest: kewl
Stats
Total Posts: 14769
Total Topics: 4138
Online Today: 2001
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: Firefox 4 get first Security Update (WebGLES, ASLR)  (Read 1635 times)
0 Members and 1 Guest are viewing this topic.
Samker
SCF Administrator
*****

KARMA: 76
Gender: Male
Location: Europe
Posts: 4780


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« on: 30. April 2011., 13:57:33 »


Mozilla has issued the first ever security update for Firefox 4.0, including a fix for two chunks of code that allowed attackers to override a key security protection baked in to recent versions of the Windows operating system.

The slip up in the two WebGLES graphics libraries, which Mozilla added to the latest version of the open-source browser, is the result of someone compiling the code without the benefit of ASLR, or address space layout randomization. The security measure, which Microsoft introduced in Windows Vista, is designed to prevent malware attacks by making it harder to locate the memory addresses of code loaded by memory-corruption exploits.

Because the library was added to Firefox 4, the bug doesn't affect earlier versions of the browser.

“Nils reported that the WebGLES libraries in the Windows version of Firefox were compiled without ASLR protection,” an advisory for the bug stated. “An attacker who found an exploitable memory corruption flaw could then use these libraries to bypass ASLR on Windows Vista and Windows 7, making the flaw as exploitable on those platforms as it would be on Windows XP or other platforms”: https://www.mozilla.org/security/announce/2011/mfsa2011-17.html

Nils, it would appear, is the hacker who took home prizes two years in a row at the annual Pwn2Own hacker competition by defeating ASLR and a similar Windows protection known as data execution prevention. He doesn't give his last name to reporters.

Firefox 4.0.1 included fixes for other bugs, including one in the XSLT generate-id() function heap and another for Miscellaneous memory safety hazards: https://www.mozilla.org/security/known-vulnerabilities/firefox40.html

Mozilla also pushed out Firefox 3.6.17, which fixed vulnerabilities in that version of the browser: https://www.mozilla.org/security/known-vulnerabilities/firefox36.html
Three of them – for bugs involving an escalation of privilege through the Java Embedding Plugin, multiple dangling pointers, and miscellaneous memory safety hazards – were rated critical.

(ElReg)
Logged

Security [CENTRAL] Forum - SCforum.info
« on: 30. April 2011., 13:57:33 »



 Logged
Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 03. February 2012., 16:39:44