<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spam Chronicles&#187; Firefox</title>
	<atom:link href="http://www.spamchronicles.com/tag/firefox/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spamchronicles.com</link>
	<description>Chronicling My Spam Explorations</description>
	<lastBuildDate>Wed, 12 Sep 2007 02:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Mozilla Firefox 2.0.0.6 Released</title>
		<link>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/</link>
		<comments>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 13:04:47 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/mozilla-firefox-2006-released/</guid>
		<description><![CDATA[Mozilla has released a security update to Firefox 2, making it the second update this month. Firefox 2.0.0.6 is available through the built-in auto-update feature or as a standalone download. One &#8220;critical&#8221; and one &#8220;moderate&#8221; vulnerabilities are patched in this update. The critical update is &#8220;Unescaped URIs passed to external programs&#8221; which is similar to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/firefoxlogo2.jpg" alt="Firefox Logo 2" align="left" /><b>Mozilla</b> has released a security update to <b>Firefox 2</b>, making it the second update this month. <a href="http://en-us.www.mozilla.com/en-US/firefox/2.0.0.6/releasenotes/" title="Jump to the Firefox 2.0.0.6 release notes">Firefox 2.0.0.6</a> is available through the built-in auto-update feature or as a <a href="http://getfirefox.com" title="Jump to the Get Firefox website">standalone download</a>.</p>
<p>One &#8220;critical&#8221; and one &#8220;moderate&#8221; vulnerabilities are patched in this update. The critical update is &#8220;Unescaped URIs passed to external programs&#8221; which is similar to the vulnerability that was found when IE 7 passed a malformed URI to Firefox.</p>
<p>The moderate vulnerability is &#8220;Privilege escalation through chrome-loaded about:blank windows&#8221;. This was dependant on add-ons creating about:blank windows.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/06/14/thunderbird-2004-released/" rel="bookmark" class="crp_title">Thunderbird 2.0.0.4 Released</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 2.0.0.5 Released</title>
		<link>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/</link>
		<comments>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/#comments</comments>
		<pubDate>Wed, 18 Jul 2007 19:19:54 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/firefox-2005-released/</guid>
		<description><![CDATA[Mozilla has released Firefox 2.0.0.5 which patches eight security vulnerabilities in Firefox. The update patched eight security vulnerabilities. The previously reported vulnerability where IE would pass a malformed URL which Firefox would then accept is one of the eight patched vulnerabilities. Two other vulnerabilities were rated as &#8220;critical&#8221; by the Firefox team. A critical rating [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/firefoxlogo2.jpg" alt="Firefox Logo 2" align="left" /><b>Mozilla</b> has released <b><a href="http://www.mozilla.com/en-US/firefox/2.0.0.5/releasenotes/" title="Jump to the Firefox 2.0.0.5 release notes">Firefox 2.0.0.5</a></b> which patches eight <b>security vulnerabilities</b> in Firefox. The update patched eight security vulnerabilities. The previously reported vulnerability where IE would pass a malformed URL which Firefox would then accept is one of the eight patched vulnerabilities.</p>
<p>Two other vulnerabilities were rated as &#8220;critical&#8221; by the Firefox team. A critical rating means:</p>
<blockquote><p>Vulnerability can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.</p></blockquote>
<p>Two vulnerabilities were rated as &#8220;high&#8221; which means:</p>
<blockquote><p>Vulnerability can be used to gather sensitive data from sites in other windows or inject data or code into those sites, requiring no more than normal browsing actions.</p></blockquote>
<p>The remaining three vulnerabilities where rated as moderate (1) or low(2).</p>
<p>The update will be installed through Firefox&#8217;s auto-update feature. You can force an update check by going to the Help on the menu and selecting &#8220;Check for Updates&#8230;&#8221;. You can also download the full version from the website and run the installation over your current installation. The update is for all languages on all operating systems.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/" rel="bookmark" class="crp_title">Vulnerability Pits Firefox Against IE</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/microsoft-patch-tuesday-for-july-2007/" rel="bookmark" class="crp_title">Microsoft Patch Tuesday for July 2007</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/18/firefox-2005-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Pits Firefox Against IE</title>
		<link>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/</link>
		<comments>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/#comments</comments>
		<pubDate>Tue, 10 Jul 2007 22:52:23 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[internet-explorer]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/vulnerability-pits-firefox-against-ie/</guid>
		<description><![CDATA[A new zero-day vulnerability exists when both Firefox 2.x and Internet Explorer are installed on the same machine. The exploit is most likely to be available on PCs with Firefox 2.0.0.2 installed due to changes made for Microsoft Vista compatibility. The general consensus of the comments are that both applications contribute the the exploit. Firefox [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/ielogo.png" alt="IE Logo" align="left" /><img src="http://www.spamchronicles.com/wp-content/uploads/2008/02/firefoxlogo2.jpg" alt="Firefox Logo 2" align="left" height="121" width="122" />A new <a href="http://larholm.com/2007/07/10/internet-explorer-0day-exploit/" title="Jump to to the entry on Larholm.com">zero-day vulnerability</a> exists when both Firefox 2.x and Internet Explorer are installed on the same machine. The exploit is most likely to be available on PCs with Firefox 2.0.0.2 installed due to changes made for Microsoft Vista compatibility.</p>
<p>The general consensus of the comments are that both applications contribute the the exploit. Firefox is the attack vector and fails to validate the malicious code but Microsoft contributes by not properly passing quotes to the command line. You need to visit a malicious website using IE in order to trigger the exploit.</p>
<p>In a response to a user comment Thor Larholm responded:</p>
<blockquote><p>&#8230; Firefox is the current attack vector but Internet Explorer is to blame for not escaping ” (quote) characters when passing on the input to the command line. I agree that Firefox could have registered its URL handler with pure DDE instead and thereby have avoided the possibility of a command line argument injection, but IE should still be able to safely launch external applications safely.</p></blockquote>
<p>What I find interesting is the complexity of the requirements leading to the exploit. Neither product is vulnerable alone since both must be installed and both products have a flaw that contributes to the vulnerability.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/04/25/mac-hacked-both-sides-miss-the-point/" rel="bookmark" class="crp_title">Mac Hacked &#8211; Both Sides Miss the Point</a></li><li><a href="http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/" rel="bookmark" class="crp_title">Firefox 2.0.0.4 &#8211; Security Update</a></li><li><a href="http://www.spamchronicles.com/2007/03/31/windows-pc-have-cursor-hole/" rel="bookmark" class="crp_title">Windows PC Have Cursor Hole</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/07/10/vulnerability-pits-firefox-against-ie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 2.0.0.4 &#8211; Security Update</title>
		<link>http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/</link>
		<comments>http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/#comments</comments>
		<pubDate>Thu, 31 May 2007 15:11:51 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[software-security-patch]]></category>

		<guid isPermaLink="false">http://www.spamchronicles.com/security-vulnerability/firefox-2004-security-update/</guid>
		<description><![CDATA[Firefox has released an update with six vulnerability fixes for Firefox 2 which ups the version number to 2.0.0.4 One of the fixes is listed as &#8220;critical&#8221;. There&#8217;s also numerous other updates and bug fixes. Enhancements include &#8220;enchancements and fixes for Windows Vista&#8221; and support for two new languages &#8211; Afrikaans (af) and Belarusian (be). [...]]]></description>
			<content:encoded><![CDATA[<p>Firefox has released an update with <a href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.4" title="Jump to the list of vulnerability fixes">six vulnerability fixes</a> for Firefox 2 which ups the version number to 2.0.0.4 One of the fixes is listed as &#8220;critical&#8221;. There&#8217;s also numerous other <a href="http://forums.mozillazine.org/viewtopic.php?p=2866044" title="Jump to the Wiki that lists the bug fixes">updates and bug fixes.</a></p>
<p>Enhancements include &#8220;enchancements and fixes for Windows Vista&#8221; and support for two new languages &#8211; Afrikaans (af) and Belarusian (be).</p>
<p>Beginning with version 2.0.0.3 there was a problem with the Java Console which is <a href="http://kb.mozillazine.org/Firefox_:_FAQs_:_Install_Java" title="Jump to the the Mozilla KB about the Java console">documented by Mozilla</a>, this also exists with this update.</p>
<blockquote><p>The Sun JRE installs a Java console extension in the program directory, which is not visible in Tools -&gt; Add-ons. JRE 6 is not compatible with Firefox 2.0.0.3 due to the manifest file setting the maximum version number to 2.0.0.0. This causes a message about the Java console being disabled when you upgrade to Firefox 2.0.0.3. If you change that number to 2.0.0.* configure the Java control panel to show the Java console and run a Java applet, sometimes the console will work, other times it will hang Firefox (so it seems to be more than just a version check problem)</p>
</blockquote>
<p>You&#8217;ll probably receive a warning that this add-on isn&#8217;t compatible when you install this update. If you need the java console refer to the FAQ for alternatives.</p>
<p>The update is available through Firefox&#8217;s built-in update function or you can <a href="http://www.mozilla.com/firefox/all.html" title="Jump to the Mozilla download page">download it from Mozilla</a>.</p>
<p>Firefox 1.5 was also updated to Firefox 1.5.0.12 and includes similar updates. Mozilla has stated they intend this to be the last update to the 1.5 branch of their product.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.spamchronicles.com/2007/07/31/mozilla-firefox-2006-released/" rel="bookmark" class="crp_title">Mozilla Firefox 2.0.0.6 Released</a></li><li><a href="http://www.spamchronicles.com/2007/07/18/firefox-2005-released/" rel="bookmark" class="crp_title">Firefox 2.0.0.5 Released</a></li><li><a href="http://www.spamchronicles.com/2007/06/14/thunderbird-2004-released/" rel="bookmark" class="crp_title">Thunderbird 2.0.0.4 Released</a></li><li><a href="http://www.spamchronicles.com/2007/04/01/block-intellitxt-ads/" rel="bookmark" class="crp_title">Block Intellitxt Ads</a></li><li><a href="http://www.spamchronicles.com/2007/07/11/apple-adds-to-patch-tuesday/" rel="bookmark" class="crp_title">Apple Adds to Patch Tuesday</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.spamchronicles.com/2007/05/31/firefox-2004-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
