Firefox 3.6 Critical Vulnerability Already Fixed

happygeek 0 Tallied Votes 523 Views Share

With the annual Pwn2Own hacking event due to kick off tomorrow, Mozilla has confirmed that Firefox 3.6 has an unpatched critical vulnerability. The fact that Pwn2Own competitors will not be able to exploit this vulnerability to claim the Firefox hacking prize will be of no interest to the millions of ordinary users who think they remain exposed and vulnerable until a patch arrives at the end of the month. But they could get protected right now if they wanted, and without changing browser clients as suggested by the German government.

The vulnerability has already been patched by Mozilla developers, according to an official posting who adds that this is "currently undergoing quality assurance testing for the fix" and so will not be made generally available until the scheduled Firefox 3.6.2 release on March 30th. However, Mozilla says that "users can ". Mozilla also recommends that people testing the 3.7 development builds "should upgrade to 3.7 alpha 3 or the latest nightly build" in order to ensure that they have this fix.

Meanwhile, according to SC Magazine the German government has "advised users not to use Mozilla Firefox" because of the flaw. Could this be the start of the downfall of Firefox? I'm certainly getting a lot more email these days from people who have made the move first from MSIE to Firefox and now to Google Chrome and seem particularly happy with the combination of speed and security that is offers, for now. How they will react when the inevitable first really big Chrome security hole appears remains to be seen. In the world of browser client security the mantra appears to be the bigger they are the harder it is not to fall, as market share attracts hacker attention. Chrome will, as it continues to gain momentum and market share, discover this soon enough I suspect. That said, so far I've been very impressed with the newest client on the block.

Of course, going back to Pwn2Own, it's . While Chrome has, so far, stood alone as secure in the face of the Pwn2Own hackers with even the Mac getting hacked in under 10 seconds last year.

Dani AI

Generated

A concise technical update and practical steps tied to the posts by and .

The bug referenced in the thread is tracked as CVE‑2010‑1028: an integer‑overflow in Firefox’s WOFF (web font) decoder that could lead to heap corruption and remote code execution. Mozilla recorded the issue as “WOFF heap corruption due to integer overflow” and fixed it in the Firefox 3.6.2 build announced March 22, 2010; CERT/CC also documented the WOFF decoder risk. (mozilla.org)

Action items for anyone still dealing with affected 3.6.x installs or archived systems: apply the security update (3.6.2 or later) or move to a maintained Firefox build. Agencies and incident responders advised immediate updates when the patch landed. For desktop Firefox, use Help → About Firefox to confirm the version and trigger the updater. (cisa.gov)

Workarounds if an immediate upgrade isn’t possible: block downloadable web fonts or prevent the WOFF decoder from running. In Firefox this can be done by toggling the hidden preference gfx.downloadable_fonts.enabled to false in about:config (extensions such as NoScript or uBlock can also block remote fonts). At the network level, filtering/blocking .woff files or applying IPS/IDS signatures that detect malicious WOFF activity provides another layer of protection. Note: disabling web fonts will change site rendering and can break icon fonts; use targeted rules where possible. (support.mozilla.org)

Summary: the issue was real, fixed promptly in 3.6.2, and practical mitigations exist for legacy environments. Turning on automatic updates and keeping browsers up to date remains the simplest, most effective protection. (mozilla.org)

Ezzaral 2,714 Posting Sage Team Colleague Featured Poster

Looks like they pushed 3.6.2 a bit early. I got an update alert today for it.

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

Cool. Not had mine yet, but then I'm using Chrome most of the time anyway now.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.