Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Vulnerability found in Firefox 3 five hours after release

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
RedEarth Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 02:40 PM
Original message
Vulnerability found in Firefox 3 five hours after release
Source: Tigervision Media

Five hours after Firefox 3 was released to the public, security firm Tipping Point claims to have found a critical security flaw, which could affect any Firefox 2.0x or Firefox 3 simply by clicking on a malicious link. Exploitation of the vulnerability could allow an attacker to execute arbitrary code.

Tipping Point said that it will not share any details about the problem since Mozilla is currently working on a fix. The discovery of vulnerability coincided with the release of Firefox 3, downloaded by more than 8 million people in the first 24 hours of its release.

The severity of this vulnerability is ranked as “high”, but an exploit requires user interaction such as clicking on a link in email or visiting a malicious web page. Once the issue is patched, Tipping Point said it will publish an advisory. The organization expects Mozilla to move swiftly into action and release the fix as soon as possible. "Working with Mozilla on past security issues, we've found them to have a good track record and expect a reasonable turnaround on this issue as well," said Tipping Point.

Read more: http://www.tgdaily.com/content/view/38018/112/
Printer Friendly | Permalink |  | Top
Runcible Spoon Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 02:41 PM
Response to Original message
1. I'm a firefox user and a big fan..thanks for the heads up..
I will be waiting for the fix and being extra vigilant about strange links...
Printer Friendly | Permalink |  | Top
 
tavalon Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 04:44 PM
Response to Reply #1
10. Another big fan here
I used to love Netscape until Explorer destroyed it and I recently found out that Firefox is related to that original Netscape. Honestly, though, with the exception of a few features, I don't see much difference between it and Explorer. But I don't like the monolithic nature of Microsoft so I'm always likely to go for the competitor, if possible.
Printer Friendly | Permalink |  | Top
 
Diclotican Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:17 PM
Response to Reply #10
20.  tavalon
tavalon

It's sad hat Netscape are no more.. I do liked Netscape for many reason.. Even that I do used the IE... And if Firefox are related to Netscape so much better;):

And yes, I do have Firefox 2.0 on my PC..

Diclotican

Sorry my bad english, not my native language
Printer Friendly | Permalink |  | Top
 
EV_Ares Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:00 PM
Response to Reply #1
15. Its prety slick but mine crashes a lot or the box pops up when I close it out
sometimes. I am using the new IE-8 right now in its Beta 1 form, Beta 2 is supposed to be out next month. Will probably end up using the Firefox 3 when they get things cleared up or both as I do a lot.
Printer Friendly | Permalink |  | Top
 
tavalon Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:32 PM
Response to Reply #15
23. The Netflix site instant viewing doesn't work on Firefox
That's pretty much the only reason we keep IE around.
Printer Friendly | Permalink |  | Top
 
sandyj999 Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 06:12 PM
Response to Reply #23
30. That's what I use my IE for...and that's all. n/t
Printer Friendly | Permalink |  | Top
 
tavalon Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 07:16 PM
Response to Reply #30
33. That's funny
That's exactly how it gets used around here. LOL
Printer Friendly | Permalink |  | Top
 
MaineDem Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 08:18 AM
Response to Reply #33
46. Same here.
:)
Printer Friendly | Permalink |  | Top
 
Chovexani Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 03:21 AM
Response to Reply #23
44. There is a Firefox plugin that lets you load an IE window in a tab
It's called IE View. Not sure if it's compatible with version 3 since I haven't upgraded yet.
Printer Friendly | Permalink |  | Top
 
Jazzgirl Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 06:00 PM
Response to Reply #15
27. I installed the Beta 1 of IE8.
I always use Firefox though. Firefox is a better browser and offers a lot more flexibility. I installed IE8 because I wanted to see what they did and it didn't really matter since I use Firefox. I will probably install Beta 2 when it comes out but I will only use it to access limited sites that require IE....like my work site.
Printer Friendly | Permalink |  | Top
 
EV_Ares Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 06:07 PM
Response to Reply #27
28. Yeah, you and I did the same thing. I like the new additions to the Fox and it is
quicker. There are just some things I use IE for so I will keep both. Especially looking forward to the new Windows, I wish I had never gone to Vista, just kind of a pain and XP was OK. The worst thing was I got Home Premium Vista, later upgraded to Ultimate for the $159.00 and then I had a problem with Bit Locker, so did a reinstall and have never been able to get Ultimate back on. Best Buy says to go to Microsoft and Microsoft says you bought it through Best Buy so there you go, out the $159.00. The more I think about it, I may finally break down and go to Apple. Have just always been a Windows guy.
Printer Friendly | Permalink |  | Top
 
Born Free Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 02:56 AM
Response to Reply #1
43.  just windows?
I wonder if this is a potential problem for linux and mac systems as well
Printer Friendly | Permalink |  | Top
 
Tangerine LaBamba Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 02:42 PM
Response to Original message
2. It'll be fixed
I have great faith in the Firefox folks. I've been using 3.0 for a bit now, and it's absolutely great!
Printer Friendly | Permalink |  | Top
 
ellenfl Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 02:58 PM
Response to Original message
3. k&r eom
Printer Friendly | Permalink |  | Top
 
barbtries Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 03:35 PM
Response to Original message
4. just upgraded
yesterday and today. i'll keep an eye out for the fix, thanks
Printer Friendly | Permalink |  | Top
 
SpiralHawk Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 03:45 PM
Response to Original message
5. "I warned you. Mercury was retrograde then. Smirk." - Ronald Reagan's Dead Republicon Astrologer
Edited on Thu Jun-19-08 03:46 PM by SpiralHawk
"You internet jockeys need to learn to pay attention to republicon occultists. Smirk."

- Ronald Reagan's Dead Republicon Astrologer
Printer Friendly | Permalink |  | Top
 
I Have A Dream Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:24 PM
Response to Reply #5
22. Yup!
:)

Printer Friendly | Permalink |  | Top
 
AllyCat Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 04:26 PM
Response to Original message
6. I love Firefox. Was so busy with life I hadn't even noticed the 3.0 upgrade
Do I wait for the fix or just upgrade now since it sounds like it affects 2.0 as well?
Printer Friendly | Permalink |  | Top
 
ElboRuum Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 04:41 PM
Response to Reply #6
9. You are vulnerable with 2, so there is no reason not to upgrade. n/t
Printer Friendly | Permalink |  | Top
 
pnorman Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 04:27 PM
Response to Original message
7. My Firefox version is 2.0.0.14
Is that the most recent before 3.0? in any event, I'll be very careful from here on. Thanks for the heads up!

pnorman
Printer Friendly | Permalink |  | Top
 
Auggie Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 04:27 PM
Response to Original message
8. I try to wait six months to upgrade any release
Printer Friendly | Permalink |  | Top
 
Psephos Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 01:02 AM
Response to Reply #8
41. I try to wait six minutes
sometimes I don't last that long
Printer Friendly | Permalink |  | Top
 
Captain Angry Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 04:45 PM
Response to Original message
11. They've been waiting for release.
This happens for every major software program that had a public beta.

The code was out there. It was hacked, and they waited. Now, it will be patched within hours. I think the people that were willing to update to 3.0 on release day are probably savvy enough to be doing their updates. This isn't going to be the same as the people still running Windows 95 that haven't patched in years.

I'm typing this response on 3.0 on my Mac. I installed 3.0 on my Mac, my work machine and my gaming rig.

I have no doubt that a patch will be available in a matter of hours.

Thanks for getting this on the front page though, it is important for people to keep an eye on where they're browsing. Considering that I am sitting on this site or a couple of jobs sites all day, I'm not worried about it. :-)
Printer Friendly | Permalink |  | Top
 
whistle Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 04:47 PM
Response to Original message
12. FireFox 3 is what exactly?
Printer Friendly | Permalink |  | Top
 
skoalyman Donating Member (751 posts) Send PM | Profile | Ignore Thu Jun-19-08 04:52 PM
Response to Reply #12
13. wait for it wait for it
Edited on Thu Jun-19-08 04:54 PM by skoalyman
NOW Que next post:evilgrin:
Printer Friendly | Permalink |  | Top
 
JBoy Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 04:54 PM
Response to Reply #12
14. Version 3.0 of the Firefox web browser
Unless it's a sequel to this movie:

Printer Friendly | Permalink |  | Top
 
OhioChick Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:01 PM
Response to Original message
16. Nice.... n/t
Printer Friendly | Permalink |  | Top
 
marshall Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:01 PM
Response to Original message
17. And I picked today to download and try out Firefox!
I just closed it down and am back to using Explorer.
Printer Friendly | Permalink |  | Top
 
merwin Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 11:39 PM
Response to Reply #17
35. You are kidding, right?
Printer Friendly | Permalink |  | Top
 
marshall Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 08:46 AM
Response to Reply #35
47. No, I had to download it to reach a website
It said it wouldn't work without Firefox. I was trying to figure out who in Malaysis was reading my blog and my stat counter directed me to a site that for some reason required Firefox to work. I downloaded it but it didn't really tell me anything.

So now I have Firefox on my computer but I'm afraid to open it again.
Printer Friendly | Permalink |  | Top
 
Cali_Democrat Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:03 PM
Response to Original message
18. Hopefully this will be fixed ASAP
I was about to download 3.0, but I think I'll wait until this issue is resolved.
Printer Friendly | Permalink |  | Top
 
merwin Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 11:40 PM
Response to Reply #18
36. It affects v2.x also, so there's no reason NOT to download 3.0
Printer Friendly | Permalink |  | Top
 
CatholicEdHead Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:06 PM
Response to Original message
19. 3.0.0.1 should be out soon
Printer Friendly | Permalink |  | Top
 
Canuckistanian Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:23 PM
Response to Original message
21. THIS is why I never get "the latest thing" right away
I always wait a few weeks, see what people are saying, THEN get the new version of whatever.

My computer is too valuable to me to take unnecessary risks.

That said, I don't expect this to be a big problem. The Mozilla team is very proficient.
Printer Friendly | Permalink |  | Top
 
merwin Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 11:40 PM
Response to Reply #21
37. See OP. This bug affects ALL versions of Firefox.
The headline is meant to shock you into reading it.
Printer Friendly | Permalink |  | Top
 
iamthebandfanman Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:38 PM
Response to Original message
24. nice, and after
that guy was on colbert last night telling everyone to go download firefox 3 cause it was the safest.

probably shoulda waited before making that kinda statement.
Printer Friendly | Permalink |  | Top
 
Jackpine Radical Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:38 PM
Response to Original message
25. Safari for me.
I just installed VMFusion on my Mac so I can run a bunch of Windoze SW, saw this story, & installed Safari on my Windoze. I had been having a few stability problems with FF & already put it on my other Windoze laptop. Too bad--FF is a nice browser, but I'm gonna use Safari as my IE alternative until they get FF straightened out.

In case you didn't know, Safari is free from Apple for the downloading.
Printer Friendly | Permalink |  | Top
 
merwin Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 11:42 PM
Response to Reply #25
38. You haven't heard of that huge gaping Safari bug on Windows, have you?
Printer Friendly | Permalink |  | Top
 
Jackpine Radical Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 12:23 AM
Response to Reply #38
40. Dammit.
No, I hadn't heard.
Printer Friendly | Permalink |  | Top
 
merwin Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 01:57 AM
Response to Reply #40
42. Looks like they just fixed it in the last few days, however their first position was that it was MS
that the exploit finally targets (using an exploit in Safari), so they refused to fix it at first. And MS put out a warning saying not to use Safari until Apple fixes it. Seems like some territorial pissing between MS and Apple to me :)
Printer Friendly | Permalink |  | Top
 
DaveJ Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 05:42 PM
Response to Original message
26. This is nothing new... the vulnerability is in V2 and V3
Edited on Thu Jun-19-08 05:43 PM by djohnson
Someone already mentioned this but it's escaped lots of folks' attention apparently.

This is vulnerability is NOT a result of upgrading. It is in Version 2 also. This "5 hours after release" line is nonsense, just coincidence. Vulnerabilities are found and fixed all the time.

Article:
...Tipping Point claims to have found a critical security flaw, which could affect any Firefox 2.0x or Firefox 3 simply by clicking on a malicious link.
Printer Friendly | Permalink |  | Top
 
sandyj999 Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 06:11 PM
Response to Original message
29. I am a fan of Firefox too and was one of the 8 Million that downloaded 3. I'll just be careful. n/t
Printer Friendly | Permalink |  | Top
 
IronLionZion Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 06:19 PM
Response to Original message
31. Good, now that it's found they can fix it
I'm a big supporter.

:toast:

Printer Friendly | Permalink |  | Top
 
CountAllVotes Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 07:14 PM
Response to Original message
32. luckily my AV caught a worm virus today
it was disguised as a firefox.exe file FYI.

Do not download this. If your antivirus catches it, DELETE it!!

:kick:
Printer Friendly | Permalink |  | Top
 
arendt Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-19-08 08:21 PM
Response to Original message
34. The gurus in my office tell me this is BOGUS FUD...
They say the bug has been around all through Firefox 2, and is well-understood. (I don't understand that, but that's what they tell me.)

When I showed them the article, they asked if Tipping Point was being paid off by Microsoft.

These guys are sharp. This story is B.S.

arendt
Printer Friendly | Permalink |  | Top
 
junior college Donating Member (290 posts) Send PM | Profile | Ignore Thu Jun-19-08 11:54 PM
Response to Original message
39. I smell FUD tactics n/t
Printer Friendly | Permalink |  | Top
 
mainegreen Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 08:11 AM
Response to Original message
45. It'll be fixed in a day or two. Few other browsers can say that.
Not IE.
Not Safari.

Opera possibly.
Printer Friendly | Permalink |  | Top
 
high density Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 08:50 AM
Response to Original message
48. Undoubtably this was discovered earlier and held back to make a bigger splash
:eyes:

Media whores.
Printer Friendly | Permalink |  | Top
 
QC Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 09:35 AM
Response to Original message
49. I have been a Firefox zealot for years, but I utterly loathe the "Awesomebar."
Aside from the juvenile idiocy of the name (it's officially the "Smart Location Bar," which is almost as bad), it is a pain in the ass to use. And, in a brilliant example of developer arrogance, you can't turn it off.

I'm going back to FF2.
Printer Friendly | Permalink |  | Top
 
Sentath Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 02:58 PM
Response to Reply #49
51. I know there are text instructions somewhere,
Printer Friendly | Permalink |  | Top
 
DailyGrind51 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 01:58 PM
Response to Original message
50. I thank you and the people on my "forward list" thank you!
Printer Friendly | Permalink |  | Top
 
RedEarth Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-20-08 03:28 PM
Response to Original message
52. Updates... Mozilla confirms Firefox 3.0 flaw, says risk minimal...
Mozilla security chief Window Snyder has confirmed the existence of a serious code execution vulnerability in the brand-new Firefox 3.0 browser.

Snyder’s confirmation follows a public warning by TippingPoint’s ZDI (Zero Day Initiative) that the flaw could lead to PC takeover hijacks if a user simply surfs to a rigged Web site with Firefox.

< SEE: Code execution vulnerability found in Firefox 3.0 >

On the Mozilla security blog, Snyder said the bug impacts Firefox versions 2.x and 3.0:

This issue is currently under investigation. To protect our users, the details of the issue will remain closed until a patch is made available. There is no public exploit, the details are private, and so the current risk to users is minimal.

At Mozilla we appreciate any report of security issues because that is how we make the browser stronger and more secure. The best way to keep Firefox users safe is to report the issues directly to Mozilla as TippingPoint has chosen to, and to wait to release details until a fix is available.

http://blogs.zdnet.com/security/?p=1304


Mozilla Sees Little Risk In Firefox 3 Flaw

Mozilla security director Window Snyder confirmed the flaw, which poses a remote code execution threat. On the Mozilla Security blog, Snyder said they are investigating the issue.

"To protect our users, the details of the issue will remain closed until a patch is made available," Snyder said. "There is no public exploit, the details are private, and so the current risk to users is minimal."

A report from TippingPoint cited a flaw that had been privately reported to them through the Zero Day Initiative program. TippingPoint acquired the vulnerability from the researcher, and provided its details to Mozilla.

The security flaw requires user interaction, such as clicking on a malicious link. If people avoid risky behavior like this, the problem poses little threat.

http://www.securitypronews.com/insiderreports/insider/spn-49-20080620MozillaSeesLittleRiskInFirefox3Flaw.html
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Tue May 07th 2024, 06:21 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC