Firefox arbitrary code flaw found

Powered by SC Magazine
 

Researchers have discovered a new flaw in Mozilla's Firefox browser that can be exploited by attackers to take over a user's computer, as long as the victim also has Internet Explorer (IE) installed.

The flaw occurs when Firefox registers the firefoxurl:// URI handler, allowing an arbitrary command line argument to invoke the program, according to an advisory released today by Secunia.

The flaw can be used to execute arbitrary code when a user visits a malicious website using IE, which then opens a vulnerable Firefox, according to Secunia.

The flaw has been confirmed in Firefox version 2.0.0.4 on a fully patched Windows XP system with Service Pack 2. It was discovered by Billy (BK) Rios, Nate Mcfeeters, and Raghav "the Pope" Dube.

Secunia ranked the flaw as "highly critical," meaning it can be exploited to execute arbitrary code.

A Mozilla representative could not immediately be reached for comment.

According to a post on xs-sniper.com, Rios, Mcfeters and Dube said that the flaw can be exploited when parameters that are part of firefoxurl: are passed to Firefox.exe as options, without validation.

"By using the firefoxurl URI, it is possible to use Internet Explorer (or other Windows-based browsers) to launch Firefox and immediately launch Javascript code," the researchers said.

In an advisory released today, FrSIRT ranked the flaw as "critical."

Researcher Thor Larholm detailed a proof-of-concept exploit for the flaw on his website. He later commented that Firefox URL handler was only added to the browser in version 2.0.0.2 so that it would be compatible with Vista.


Firefox arbitrary code flaw found
 
 
 
Top Stories
Matching databases to Linux distros
Reviewed: OS-repository DBMSs, MariaDB vs MySQL.
 
Coalition's NBN cost-benefit study finds in favour of MTM
FTTP costs too much, would take too long.
 
Who'd have picked a BlackBerry for the Internet of Things?
[Blog] BlackBerry has a more secure future in the physical world.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  70%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  11%
 
Denial of service attacks
  6%
 
Insider threats
  10%
TOTAL VOTES: 696

Vote