New User, Welcome!     Login

Mozilla Firefox 2

[USN-667-1] Firefox and xulrunner vulnerabilities

Ubuntu 6.06 LTS:
  firefox                         1.5.dfsg+1.5.0.15~prepatch080614h-0ubuntu1

Ubuntu 7.10:
  firefox                         2.0.0.18+nobinonly-0ubuntu0.7.10

Ubuntu 8.04 LTS:
  firefox-3.0                     3.0.4+nobinonly-0ubuntu0.8.04.1
  xulrunner-1.9                   1.9.0.4+nobinonly-0ubuntu0.8.04.1


Windows Media Audio Voice remote code execution

tricking the victim into opening an attacker-controlled web page. This
can be done by specifying a malformed .wma file as a webpage
background sound (bgsound tags) or by embedding windows media player
in a web page (embed tags). This attack works with multiple browsers
(tested on Internet Explorer 6, Internet Explorer 7 and Mozilla
Firefox 2 under Windows XP, other browsers and Windows version are
affected as well).

#####
#PoC#
#####

Stored XSS vulnerability in NPDS REvolution

<script>alert(document.cookie)</script>


For these purposes use "tamper data" or "firebug" plugin to firefox
2)
Open "http://host/stats.php" page from other user.

Solution: Upgrade to the most recent verison



[USN-930-3] Firefox regression

the necessary changes.

Details follow:

USN-930-1 fixed vulnerabilities in Firefox. Due to a software packaging
problem, the Firefox 3.6 update could not be installed when the firefox-2
package was also installed. This update fixes the problem and updates
apturl for the change.

Original advisory details:


WASC Announcement: The Script Mapping Project Results and Call for Participation

The Web Application Security Consortium is pleased to announce the first results 
of the Script Mapping project! At this stage in the project we were able to cover
most of the test cases for Internet Explorer 7, Firefox 2 and Safari 3.

The results can be found on the project page:
http://www.webappsec.org/projects/scriptmapping/

Project Description:




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!