SHARE
Facebook X Pinterest WhatsApp

Firefox 3.0.4 is out fixing some ‘neat’ flaws

Nov 13, 2008
sr-firefox3.jpg

From the “weird and wacky ways browser can be exploited” files:

As I noted last week Firefox 3.0.4 is out now (technically late yesterday) fixing at least 9 security fixes four of which are labeled as “critical”.

There are (as usual) some flawa that I consider to be really interesting – in that they are attack vectors that I just haven’t heard off or seen before. One of them is a Cross Site Scripting (XSS) and JavaScript privilege escalation via a Firefox browser session restore.

I love the Session Restore feature as I’m the kind of user that always has 10+ tabs open all the time. To think that it could be used as a vehicle to exploit me is “interesting” to say the least.  According to Mozilla, as a result of that flaw potentially, “any otherwise unexploitable crash can be used to force the user into the session restore state.”

Mozilla also provides a fix for a flaw that could have enabled an attacker to steal user information from local shortcut files. Shortcut files?! Really? Mozilla only labels this flaw as “moderate” since they view it as being a little complex to execute. The way the attack would work is that .url shortcut files could potentially be used to read local cache information if the user downloaded both an HTML file and a .url shortcut.

As part of the update Mozilla is also updating Firefox 2.x to 2.0.0.19 though it’s clear that the Firefox 2.x’s days are numbered. With Firefox 3.1 around the corner (the Beta 2 release is likely next week now with a test day scheduled for Friday), it will soon be time for Firefox 3.x users to upgrade too.

Recommended for you...

Facebook Becomes Meta, But Did It Move Too Soon?
Rob Enderle
Oct 29, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
Why AMD Has Been So Successful: Mark Papermaster
Rob Enderle
Sep 9, 2021
Another Crazy Week in Cybersecurity
Paul Shread
Jul 2, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.