This is not phishing, this is art!
Read more here what this is about.


Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters
This is not phishing, this is art!
Read more here what this is about.




Privacy Policy

Mozilla confirms critical Firefox bug

Slates patch for March 30; flaw can't be used in upcoming Pwn2Own hack contest

March 19, 2010 04:05 PM ET

Computerworld - Mozilla yesterday confirmed a critical vulnerability in the newest version of Firefox, and said it would plug the hole by the end of the month.

Although the patch won't be added to Firefox before next week's Pwn2Own browser hacking challenge, researchers won't be allowed to use the flaw, according to the contest's organizer.

"The vulnerability was determined to be critical and could result in remote code execution by an attacker," Mozilla acknowledged in a post to its security blog late Thursday. "The vulnerability has been patched by developers and we are currently undergoing quality assurance testing for the fix."

Firefox 3.6, which Mozilla launched in January, is affected, Mozilla said, adding that it would be patched in version 3.6.2, currently slated to ship on March 30.

The bug was disclosed by Russian researcher Evgeny Legerov a month ago in a message posted on a forum hosted by Immunity, the Miami Beach, Fla. developer best known for its Canvas penetration testing framework. Legerov works for Moscow-based Intevydis, which produces the VulnDisco add-on for Canvas.

Legerov did not publish attack code, and initially refused to provide details to Mozilla, according to a March 4 entry he posted on his blog. "I've ignored e-mails ... from Mozilla, please do not waste my and your time anymore," Legerov wrote. The blog has since been deleted, but is still available via Google's cache.

In comments appended to a vulnerability alert published by Danish bug tracker Secunia, several users questioned Legerov's motives for making the announcement, while others chided Secunia for not thoroughly testing the flaw or claimed that it was all a hoax.

Mozilla yesterday said Legerov had eventually sent them "sufficient details to reproduce and analyze the issue."

Until the March 30 patch is released, users can upgrade Firefox to the beta of version 3.6.2, which includes the fix, by downloading the preview.

Although Apple and Google have recently updated Safari and Chrome, respectively -- beefing up the browsers' security before the $100,000 Pwn2Own hacking contest starts March 24 -- the version of Firefox that will be used in the challenge will lack the patch for Legerov's vulnerability. Pwn2Own will pit only production versions of Chrome, Firefox, Internet Explorer (IE) and Safari against the hacking talents of researchers.

However, that doesn't mean hackers will be able to use the bug to claim one of the $10,000 prizes for successfully exploiting Firefox. "We will have our entire research team on-site so that we can do our best to ensure that known issues such as this one do not turn up at our contest," said Aaron Portnoy, a research team lead with 3Com TippingPoint, the company sponsoring Pwn2Own.

Portnoy, who organized the fourth annual contest, has predicted that Microsoft's IE8 will be the first browser to fall during the three-day event.

Mozilla will also patch Firefox 3.0 (with 3.0.19) and Firefox 3.5 (with 3.5.9) on March 30. Firefox 3.0.19 will be the final security update for the browser Mozilla debuted in mid-2008.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer or subscribe to Gregg's RSS feed Keizer RSS. His e-mail address is gkeizer@ix.netcom.com. metatag data

Read more about security in Computerworld's Security Knowledge Center.



Jump to comments

Firefox bug

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Data Protection for Businesses with Remote Offices & Multiple Locations
Hardware and software solutions for data backup & restore should be easy to integrate into the existing environment, provide easy-to-manage data protection and...

Secure Your Wireless LAN: How to protect against security breaches
As Wi-Fi technology constantly grows, companies must protect themselves by adopting solutions that secure their wireless local-area network. This HP white paper will...

Complying with PCI without Going Broke
Do a better job saving money and securing your data. Watch now.

Maintain Continuity of Operations with a Disaster Tolerance Strategy
IT risks must be considered as serious as any other significant business risk. When was the last time you assessed your IT risks?...

Get the Instruments You Need to Become an IT Security Hero
View an online demo that shows how you can quickly bullet-proof your internet security with the new iPrism 6.4 web filter, and you'll...


IT Jobs

This is not phishing, this is art!
Read more here what this is about.
This is not phishing, this is art!
Read more here what this is about.