Members
Stats
  • Total Posts: 28514
  • Total Topics: 8240
  • Online Today: 867
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)












Author Topic: Mozilla squashes 4 critical bugs in Firefox (Marlinspike, Thunderbird-SeaMonkey)  (Read 1995 times)

0 Members and 1 Guest are viewing this topic.

Samker

  • SCF Administrator
  • *****
  • Posts: 7206
  • KARMA: 291
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum


Mozilla on Monday issued an update for Firefox that fixes four critical security bugs in the popular open-source browser, including one exposed last week that could make it easy for attackers to spoof SSL certificates used to secure websites.

The vulnerability meant Firefox could be tricked by rogue certificates, a potentially dangerous scenario that could allow attackers to create convincing-looking forgeries of websites used for banking, email and other sensitive services. The technique works by adding a simple null string character to several certificate fields and was independently reported at the Black Hat security conference by researchers Moxie Marlinspike and Dan Kaminsky.

"We strongly recommend that all Firefox users upgrade to this latest release," a statement on Mozilla's website read: http://blog.mozilla.com/blog/2009/08/03/firefox-3-5-2-and-3-0-13-security-updates-now-available-for-download/

The SSL vulnerability allowed Marlinspike to create what he called a universal wildcard certificate that caused Firefox to authenticate every domain name on the internet. He did so by applying for a normal certificate for his website thoughtcrime.org. In the commonName field he listed the site as *\0.thoughtcrime.org, causing the browser to believe the certificate was universally valid.

Mozilla said three of its other products - Thunderbird, SeaMonkey and NSS - are vulnerable to the same attack. Presumably, fixes for those applications will be forthcoming.

The patch plugged three other critical holes, including crashes that carried evidence of memory corruption, a heap overflow in certificate regexp parsing and a Chrome privilege escalation due to an incorrectly cached wrapper. Vulnerabilities rated critical typically allow an attacker to remotely execute malware on a vulnerable machine with minimal action needed on the part of the end user.

The patch brings the most recent version of Firefox to 3.5.2. For those who are unable to upgrade to version 3.5 of the browser, the open-source outfit issued a patch that brings the older version to 3.0.13. The vulnerabilities apply to the Windows, Mac and Linux platforms.

It's the second time in 18 days that Mozilla has fixed critical bugs in its flagship browser. Two weeks ago, the foundation rushed out a patch to repair a javascript-based memory corruption bug that was already being targeted in the wild.

Marlinspike said most internet client-side software that implements SSL are vulnerable to the null-string bug, so we'd expect this to be the first of many patches fixing that vulnerability.

(The Register)

Samker's Computer Forum - SCforum.info





mashed

  • SCF Member
  • **
  • Posts: 63
  • KARMA: 10
  • Gender: Male
    • Stressed
thanks for the info, i was wondering what the update was for, mine auto updated an hour or two ago

Darksat

  • SCF VIP Member
  • *****
  • Posts: 20
  • KARMA: 2
    • Darksat Security Forums
Interesting, fairly simple way to go about it though.
Surely though whoever issued him the SSL certificate should have picked up on that one

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising