Server Help Forum Index Server Help
Community forums for Subgame, ASSS, and bots
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   StatisticsStatistics   RegisterRegister 
 ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin (SSL) 

Server Help | ASSS Wiki (0) | Shanky.com
Go Mozilla!

 
Post new topic   Reply to topic Printable version
 View previous topic  SSZ Battlefield 1942 Post :: Post hahaha classic  View next topic  
Author Message
Gravitron
VIE Vet


Age:43
Gender:Gender:Male
Joined: Aug 02 2002
Posts: 993
Location: Israel
Offline

PostPosted: Sun Jan 09, 2005 3:30 am   Post maybe stupid    Post subject: Go Mozilla! Reply to topic Reply with quote

To: BugTraq
Subject: [ GLSA 200501-03 ] Mozilla, Firefox, Thunderbird: Various vulnerabilities
Date: Jan 5 2005 9:09AM
Author: Thierry Carrez <koon gentoo org>
Message-ID: <41DBAEC4.60100@gentoo.org>


- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200501-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: Mozilla, Firefox, Thunderbird: Various vulnerabilities
Date: January 05, 2005
Bugs: #76112, #68976, #70749
ID: 200501-03

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Various vulnerabilities were found and fixed in Mozilla-based products,
ranging from a potential buffer overflow and temporary files disclosure
to anti-spoofing issues.

Background
==========

Mozilla is a popular web browser that includes a mail and newsreader.
Mozilla Firefox and Mozilla Thunderbird are respectively the
next-generation browser and mail client from the Mozilla project.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 mozilla < 1.7.5 >= 1.7.5
2 mozilla-bin < 1.7.5 >= 1.7.5
3 mozilla-firefox < 1.0 >= 1.0
4 mozilla-firefox-bin < 1.0 >= 1.0
5 mozilla-thunderbird < 0.9 >= 0.9
6 mozilla-thunderbird-bin < 0.9 >= 0.9
-------------------------------------------------------------------
6 affected packages on all of their supported architectures.
-------------------------------------------------------------------

Description
===========

Maurycy Prodeus from isec.pl found a potentially exploitable buffer
overflow in the handling of NNTP URLs. Furthermore, Martin (from
ptraced.net) discovered that temporary files in recent versions of
Mozilla-based products were sometimes stored world-readable with
predictable names. The Mozilla Team also fixed a way of spoofing
filenames in Firefox's "What should Firefox do with this file" dialog
boxes and a potential information leak about the existence of local
filenames.

Impact
======

A remote attacker could craft a malicious NNTP link and entice a user
to click it, potentially resulting in the execution of arbitrary code
with the rights of the user running the browser. A local attacker could
leverage the temporary file vulnerability to read the contents of
another user's attachments or downloads. A remote attacker could also
design a malicious web page that would allow to spoof filenames if the
user uses the "Open with..." function in Firefox, or retrieve
information on the presence of specific files in the local filesystem.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Mozilla users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-www/mozilla-1.7.5"

All Mozilla binary users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-www/mozilla-bin-1.7.5"

All Firefox users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-www/mozilla-firefox-1.0"

All Firefox binary users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-www/mozilla-firefox-bin-1.0"

All Thunderbird users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose
">=mail-client/mozilla-thunderbird-0.9"

All Thunderbird binary users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose
">=mail-client/mozilla-thunderbird-bin-0.9"

References
==========

[ 1 ] isec.pl Advisory
http://isec.pl/vulnerabilities/isec-0020-mozilla.txt
[ 2 ] Martin (from ptraced.net) Advisory
http://broadcast.ptraced.net/advisories/008-firefox.thunderbird.txt
[ 3 ] Secunia Advisory SA13144
http://secunia.com/advisories/13144/

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

http://security.gentoo.org/glsa/glsa-200501-03.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security gentoo org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2004 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.0
Back to top
View users profile Send private message Add User to Ignore List Visit posters website AIM Address Yahoo Messenger MSN Messenger
Assassin2684
Server Help Squatter


Age:34
Gender:Not sure
Joined: Jul 27 2004
Posts: 990
Location: Florida
Offline

PostPosted: Sun Jan 09, 2005 8:16 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

Nice... I use mozilla firefox.
Back to top
View users profile Send private message Add User to Ignore List AIM Address
CypherJF
I gargle nitroglycerin


Gender:Gender:Male
Joined: Aug 14 2003
Posts: 2582
Location: USA
Offline

PostPosted: Sun Jan 09, 2005 8:22 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

Oh the pains.. however. from slashdot, today...
Quote:
"Secunia is reporting on three vulnerabilities in IE6 running on XP SP2. Any of these, in combination with an inappropriate behaviour where the ActiveX Data Object (ADO) model can write arbitrary files, can be exploited to compromise a user's system. Moreover, the vulnerability can be used to delete files from the user's system. Secunia says 'Solution: Use another product.'"


errm can we say, more severe? here are the URLs involved:

http://secunia.com/advisories/12889/

http://www.jmcardle.com/?postid=77
_________________
Performance is often the art of cheating carefully. - James Gosling
Back to top
View users profile Send private message Add User to Ignore List
Purge
Episode I > Eposide III
Jar-Jar is kool


Age:36
Gender:Gender:Male
Joined: Sep 08 2004
Posts: 2019
Offline

PostPosted: Sun Jan 09, 2005 10:00 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

I like the neat mIRC plugin in the Mozilla browser. sa_tongue.gif
Back to top
View users profile Send private message Add User to Ignore List
SuSE
Me measures good


Joined: Dec 02 2002
Posts: 2307
Offline

PostPosted: Sun Jan 09, 2005 12:16 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

I think he was praising Mozilla's swift patching.
Back to top
View users profile Send private message Add User to Ignore List Send email Visit posters website
Cyan~Fire
I'll count you!
I'll count you!


Age:37
Gender:Gender:Male
Joined: Jul 14 2003
Posts: 4608
Location: A Dream
Offline

PostPosted: Sun Jan 09, 2005 12:50 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Hopefully so.

I also really, really like Adblock. I haven't seen a flash banner ad for ages and I have all the major servers blocked.
_________________
This help is informational only. No representation is made or warranty given as to its content. User assumes all risk of use. Cyan~Fire assumes no responsibility for any loss or delay resulting from such use.
Wise men STILL seek Him.
Back to top
View users profile Send private message Add User to Ignore List Visit posters website
Smong
Server Help Squatter


Joined: 1043048991
Posts: 0x91E
Offline

PostPosted: Sun Jan 09, 2005 1:11 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Jan 5th? I'm sure I emerged firefox-1.0 before that date so is this guy just finding bugs in old versions and being a scaremonger? Or do they release several versions of firefox over a period of time all named version 1.0?
Back to top
View users profile Send private message Add User to Ignore List Visit posters website MSN Messenger
Cyan~Fire
I'll count you!
I'll count you!


Age:37
Gender:Gender:Male
Joined: Jul 14 2003
Posts: 4608
Location: A Dream
Offline

PostPosted: Sun Jan 09, 2005 3:43 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Oh, it is old versions.

Grav wrote:
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 mozilla < 1.7.5 >= 1.7.5
2 mozilla-bin < 1.7.5 >= 1.7.5
3 mozilla-firefox < 1.0 >= 1.0
4 mozilla-firefox-bin < 1.0 >= 1.0
5 mozilla-thunderbird < 0.9 >= 0.9
6 mozilla-thunderbird-bin < 0.9 >= 0.9

is actually a table on the webpage, which isn't very clear in plaintext.
Back to top
View users profile Send private message Add User to Ignore List Visit posters website
Gravitron
VIE Vet


Age:43
Gender:Gender:Male
Joined: Aug 02 2002
Posts: 993
Location: Israel
Offline

PostPosted: Tue Jan 11, 2005 7:27 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Yes Cypher, well, this will be someone else's problem.
I don't use XP, so it does not affect me, see.

I'm impervious to XP flaws, I'm impervious to firefox flaws.
GG, I win.
Back to top
View users profile Send private message Add User to Ignore List Visit posters website AIM Address Yahoo Messenger MSN Messenger
CypherJF
I gargle nitroglycerin


Gender:Gender:Male
Joined: Aug 14 2003
Posts: 2582
Location: USA
Offline

PostPosted: Tue Jan 11, 2005 9:21 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

I'm sure there is a flaw in your logic. But we wont go into that. icon_smile.gif
Back to top
View users profile Send private message Add User to Ignore List
Display posts from previous:   
Post new topic   Reply to topic    Server Help Forum Index -> Trash Talk All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
View online users | View Statistics | View Ignored List


Software by php BB © php BB Group
Server Load: 36 page(s) served in previous 5 minutes.

phpBB Created this page in 0.862349 seconds : 32 queries executed (91.7%): GZIP compression disabled