|
-
July 19th, 2009, 11:58 AM
#1
FF 3.5.1 Vulnerable
FireFox 3.5.1 has a vulnerability:
http://isc.sans.org/diary.html?storyid=6829&rss
There is no patch yet
Although Javascript access can be restricted with applications such as the NoScript Add-On, it may still be possible for the browser to be exploited if an untrusted website is loaded
-
July 20th, 2009, 10:22 AM
#2
Here is what Mozilla guys had to say about it
"We do not believe this is any kind of boundary condition, but a
non-exploitable denial-of-service due to memory exhaustion."
http://blog.mozilla.com/security/200...cve-2009-2479/
More :
http://isc.sans.org/diary.html?storyid=6838
Parth Maniar,
CISSP, CISM, CISA, SSCP
*Thank you GOD*
Greater the Difficulty, SWEETER the Victory.
Believe in yourself.
-
July 20th, 2009, 10:24 AM
#3
WHY THE HELL ARE PEOPLE STILL USING FIREFOX ! :x
Parth Maniar,
CISSP, CISM, CISA, SSCP
*Thank you GOD*
Greater the Difficulty, SWEETER the Victory.
Believe in yourself.
-
July 20th, 2009, 11:16 AM
#4
 Originally Posted by ByTeWrangler
WHY THE HELL ARE PEOPLE STILL USING FIREFOX ! :x
Because there are people who are ignorant and believe, worship the following statement.
The Firefox Web Browser is the faster, more secure, and fully customizable way to surf the web.
Plus your not cool unless you tell everyone to ditch other browsers and use FF cause it's so much uber better then the others...
-
July 20th, 2009, 11:26 AM
#5
Don't worry about it ByTe~, it really isn't a problem; the British government are still using IE6 
http://antionline.com/showthread.php?t=278339
It does look as though this might be a cross browser problem though, as your link mentions that it was first tried on IE8? I notice that my Secunia PSI still shows IE8 as vulnerable to XSS due to character set inheritance.
FireFox and Opera share these plugin vulnerabilities with IE8:
Real Player 11.x
Sun Java JRE 1.6x/6x (x2)
Secunia have yet to mention the memory exhaustion issue.
All the vulnerabilities are unpatched 
As for your question:
WHY THE HELL ARE PEOPLE STILL USING FIREFOX ! :x
Because they still run Windows 2000, although the latest Opera will also run on that, and would possibly be a better bet?
Given that MS are still supporting Windows 2000, I am guessing that they must also be supporting IE6, as it is the latest version that will run with that OS.
I would still prefer FF and Opera to IE6 as they have more functionality and are likely to be more secure.
I will check an IE6/Windows 2000 box later today.

EDIT:
On a fully patched Windows 2000/IE6 box the IE shows as vulnerable per-se, Opera and FF 3.0 do not.
Last edited by nihil; July 21st, 2009 at 06:07 PM.
-
July 20th, 2009, 02:02 PM
#6
Junior Member
So then what browser do you all recommend?
Falcis
-
July 20th, 2009, 05:30 PM
#7
I used K-Meleon for a few days... turns out that it is as much of a memory hog as FF, but more buggy. Haven't spent much time in IE8 yet, but I am thinking about giving it a shot. I have yet to find a browser that doesn't drive me to strong drink...
\"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"
-HST
-
July 20th, 2009, 06:48 PM
#8
Use opera for all your browsing needs.
There are webpages where Opera will fail use IE there. However ensure every URL that you visit using IE is know (like microsoft, yahoo, windows live) but not links through google use !
You will never get infected through a webpage if you are visiting well known sites which take enough measure's to ensure integrity of their sites. But if you wander of searching through good it's better to use opera.
Parth Maniar,
CISSP, CISM, CISA, SSCP
*Thank you GOD*
Greater the Difficulty, SWEETER the Victory.
Believe in yourself.
-
July 20th, 2009, 07:49 PM
#9
 Originally Posted by ByTeWrangler
Use opera for all your browsing needs.
There are webpages where Opera will fail use IE there. However ensure every URL that you visit using IE is know (like microsoft, yahoo, windows live) but not links through google use !
You will never get infected through a webpage if you are visiting well known sites which take enough measure's to ensure integrity of their sites. But if you wander of searching through good it's better to use opera.
Sounds like a great browsing solution. Use Opera for all of your browsing needs, except where it doesn't work... use a different browser there.
\"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"
-HST
-
July 21st, 2009, 05:13 AM
#10
Junior Member
 Originally Posted by westin
Sounds like a great browsing solution. Use Opera for all of your browsing needs, except where it doesn't work... use a different browser there. 
And don't you dare go to websites you haven't heard of! Screw discovering new things!
Similar Threads
-
By Black Cluster in forum Security News
Replies: 0
Last Post: September 30th, 2005, 11:20 AM
-
By cleanbash in forum Microsoft Security Discussions
Replies: 7
Last Post: October 13th, 2003, 10:30 PM
-
By Fakeboy in forum Web Development
Replies: 2
Last Post: July 12th, 2002, 04:20 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|