Mozilla confirms critical Firefox bug
Slates patch for March 30; flaw can't be used in upcoming Pwn2Own hack contest
March 19, 2010 04:05 PM ETBrowser wars
- Windows XP: No IE9 for you
- Hands on: Internet Explorer 9 Platform Preview shows speed, not much else
- A primer on Microsoft's IE9 browser
- IE9 proves Microsoft is back in the browser battle, says analyst
- Microsoft unveils IE9 public preview
- Mozilla pitches Firefox 3.6 upgrade offer to users
- Opera confirms critical browser bug
- Small browser makers bitter over ballot screen layout
- Opera downloads triple after browser ballot screen debut
- Researchers develop 3D graphics capability for Firefox
Computerworld - Mozilla yesterday confirmed a critical vulnerability in the newest version of Firefox, and said it would plug the hole by the end of the month.
Although the patch won't be added to Firefox before next week's Pwn2Own browser hacking challenge, researchers won't be allowed to use the flaw, according to the contest's organizer.
"The vulnerability was determined to be critical and could result in remote code execution by an attacker," Mozilla acknowledged in a post to its security blog late Thursday. "The vulnerability has been patched by developers and we are currently undergoing quality assurance testing for the fix."
Firefox 3.6, which Mozilla launched in January, is affected, Mozilla said, adding that it would be patched in version 3.6.2, currently slated to ship on March 30.
The bug was disclosed by Russian researcher Evgeny Legerov a month ago in a message posted on a forum hosted by Immunity, the Miami Beach, Fla. developer best known for its Canvas penetration testing framework. Legerov works for Moscow-based Intevydis, which produces the VulnDisco add-on for Canvas.
Legerov did not publish attack code, and initially refused to provide details to Mozilla, according to a March 4 entry he posted on his blog. "I've ignored e-mails ... from Mozilla, please do not waste my and your time anymore," Legerov wrote. The blog has since been deleted, but is still available via Google's cache.
In comments appended to a vulnerability alert published by Danish bug tracker Secunia, several users questioned Legerov's motives for making the announcement, while others chided Secunia for not thoroughly testing the flaw or claimed that it was all a hoax.
Mozilla yesterday said Legerov had eventually sent them "sufficient details to reproduce and analyze the issue."
Until the March 30 patch is released, users can upgrade Firefox to the beta of version 3.6.2, which includes the fix, by downloading the preview.
Although Apple and Google have recently updated Safari and Chrome, respectively -- beefing up the browsers' security before the $100,000 Pwn2Own hacking contest starts March 24 -- the version of Firefox that will be used in the challenge will lack the patch for Legerov's vulnerability. Pwn2Own will pit only production versions of Chrome, Firefox, Internet Explorer (IE) and Safari against the hacking talents of researchers.
However, that doesn't mean hackers will be able to use the bug to claim one of the $10,000 prizes for successfully exploiting Firefox. "We will have our entire research team on-site so that we can do our best to ensure that known issues such as this one do not turn up at our contest," said Aaron Portnoy, a research team lead with 3Com TippingPoint, the company sponsoring Pwn2Own.
Portnoy, who organized the fourth annual contest, has predicted that Microsoft's IE8 will be the first browser to fall during the three-day event.
Mozilla will also patch Firefox 3.0 (with 3.0.19) and Firefox 3.5 (with 3.5.9) on March 30. Firefox 3.0.19 will be the final security update for the browser Mozilla debuted in mid-2008.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@ix.netcom.com. metatag data
Read more about security in Computerworld's Security Knowledge Center.
Firefox bug
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Data Protection for Businesses with Remote Offices & Multiple Locations
Hardware and software solutions for data backup & restore should be easy to integrate into the existing environment, provide easy-to-manage data protection and... ![]()
Best Practices for Log Monitoring
Watch Now!
Secure Your Wireless LAN: How to protect against security breaches
As Wi-Fi technology constantly grows, companies must protect themselves by adopting solutions that secure their wireless local-area network. This HP white paper will... ![]()
Complying with PCI without Going Broke
Do a better job saving money and securing your data. Watch now.
Maintain Continuity of Operations with a Disaster Tolerance Strategy
IT risks must be considered as serious as any other significant business risk. When was the last time you assessed your IT risks?... ![]()
Get the Instruments You Need to Become an IT Security Hero
View an online demo that shows how you can quickly bullet-proof your internet security with the new iPrism 6.4 web filter, and you'll...
Sunny Skies Ahead- Evolving Your Security Infrastructure for the Cloud
Register for this webcast now!
Mobility Management for Dummies
Download Now ![]()




