Update: Firefox update will patch CSRF bug, Mozilla says
Delayed Firefox 3.6.14, 3.5.17 to ship March 1, fix cross-site request forgery bug that can be exploited via Flash
Computerworld - Mozilla said late Wednesday that it will ship security updates to Firefox 3.5 and Firefox 3.6 next week that will include a patch for a bug that can be exploited using a malicious Adobe Flash file.
(Editor's note: An earlier version of this story, published before Mozilla responded to a request for comment, said company meeting notes suggested that the Firefox security updates would not include the patch.)
Firefox 3.5.17 and Firefox 3.6.14 will now appear Tuesday, March 1, Mozilla disclosed in meeting notes published today.
Originally slated for release Feb. 14, the security updates were held while Mozilla developers investigated a bug that affected some, though not all, users of the betas. According to Mozilla, the bug caused some copies of the updates to repeatedly crash. Mozilla then backed out a recent fix to retest the betas.
Around the same time, another problem -- a separate cross-site request forgery (CSRF) vulnerability -- surfaced that Mozilla needed to patch. "Adobe is pressing for a release due to a public CSRF issue," Mozilla said last week.
The vulnerability is in Firefox, but Adobe's involved because the vulnerability can be exploited using a malformed Flash file.
According to patch information posted Feb. 8 by the open-source Ruby on Rails Web development framework, and a follow-up message two days later on a security mailing list, the CSRF bug can be exploited by "Certain combinations of browser plug-ins and HTTP redirects."
An attacker could exploit the vulnerability to bypass the built-in CSRF protections of Ruby on Rails -- and that of Django, another Web development platform, which also patched its products earlier this month -- and successfully attack a Web application built with those tools.
The security mailing list message posted Feb. 10 spelled out several affected browsers, including Firefox -- including an earlier beta of Firefox 4 -- as well as Google's Chrome and Apple's Safari on both Windows and Mac OS.
That same message also said that a Google security researcher had first reported the CSRF vulnerability.
Last week, an Adobe spokeswoman said she knew nothing about a potential zero-day that would impact its software and/or Firefox.
Mozilla will patch the CSRF flaw in both Firefox 2.5.17 and Firefox 3.6.14 when they ship next week, a spokeswoman for that company confirmed late Wednesday.
The timing of the update may help Firefox survive the Pwn2Own, the hacking contest that kicks off March 9 at the CanSecWest security conference in Vancouver, British Columbia.
Firefox will be one of four browsers -- the others are Chrome, Safari and Microsoft's Internet Explorer -- that will be targeted by attackers hoping to walk off with $15,000 or $20,000 in cash. Pwn2Own's rules state that the targeted browsers will be "the latest release candidate at the time of the contest," meaning that researchers will have to tackle Firefox 3.6.14.
Last year, Mozilla confirmed a critical vulnerability in Firefox less than a week before 2010's Pwn2Own, but said it wouldn't fix the flaw until after the contest. Pwn2Own organizers then ruled that hackers would not be allowed to use the vulnerability to exploit Firefox.
Pwn2Own 2011
- iPhone, BlackBerry tumble to Pwn2Own hackers
- Researcher chains three exploits to take down IE8 at Pwn2Own
- Safari, IE hacked first at Pwn2Own
- Researcher blows $15K by reporting bug to Google
- Microsoft won't patch IE before Pwn2Own
- Apple to patch Safari before Pwn2Own, say researchers
- Mozilla follows Google, patches Firefox as prep for Pwn2Own
- Three-time Pwn2Own winner knocks hacking contest rules
- Familiar faces, new names step up at Pwn2Own hacking contest
- Update: Firefox update will patch CSRF bug, Mozilla says
Read more about Security in Computerworld's Security Topic Center.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Securing Internet File Transfers This solution brief describes the four essential elements of secure Internet transfers.
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
