+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    sagar.best's Avatar
    sagar.best is offline Senior sagar.best will become famous soon enough
    Join Date
    Oct 2008
    Location
    kanpur
    Posts
    623
    Thanks
    3
    Thanked 14 Times in 12 Posts
    Feedback Score
    0

    Default Firefox 3.0.4 is out fixing some 'neat' flaws

    As I noted last week Firefox 3.0.4 is out now (technically late yesterday) fixing at least 9 security fixes four of which are labeled as "critical".

    There are (as usual) some flawa that I consider to be really interesting - in that they are attack vectors that I just haven't heard off or seen before. One of them is a Cross Site Scripting (XSS) and JavaScript privilege escalation via a Firefox browser

    I love the Session Restore feature as I'm the kind of user that always has 10+ tabs open all the time. To think that it could be used as a vehicle to exploit me is "interesting" to say the least. According to Mozilla, as a result of that flaw potentially, "any otherwise unexploitable crash can be used to force the user into the session restore state."

    Mozilla also provides a fix for a flaw that could have enabled an attacker to steal user information from local shortcut files. Shortcut files?! Really? Mozilla only labels this flaw as "moderate" since they view it as being a little complex to execute. The way the attack would work is that .url shortcut files could potentially be used to read local cache information if the user downloaded both an HTML file and a .url shortcut.

    As part of the update Mozilla is also updating Firefox 2.x to 2.0.0.19 though it's clear that the Firefox 2.x's days are numbered. With Firefox 3.1 around the corner (the Beta 2 release is likely next week now with a test day scheduled for Friday), it will soon be time for Firefox 3.x users to upgrade too.

  2. #2
    Join Date
    Apr 2008
    Location
    USA, New York -- Born in India
    Posts
    4,811
    Thanks
    510
    Thanked 200 Times in 159 Posts
    Feedback Score
    4 (100%)

    Default

    Hmm, thats really good of them. This is what makes people feel so much safer and at ease on the net.
    Amir Mullick, SEO and Internet Marketer.
    Wanna learn more about SEO? Visit my SEO Blog and Gadgets Blog

  3. #3
    sagar.best's Avatar
    sagar.best is offline Senior sagar.best will become famous soon enough
    Join Date
    Oct 2008
    Location
    kanpur
    Posts
    623
    Thanks
    3
    Thanked 14 Times in 12 Posts
    Feedback Score
    0

    Default

    Quote Originally Posted by Amirmullick3 View Post
    Hmm, thats really good of them. This is what makes people feel so much safer and at ease on the net.
    yea firefox rockssss....!!!

Similar Threads

  1. Mozilla tricks - Latest 7 mozilla firefox tricks
    By sagar.best in forum All Other Search Engines
    Replies: 0
    Last Post: 11-20-2008, 03:28 AM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts