Firefox attack code posted by security reseracher
TG Daily - All News —
... fixing critical exploits in their products, even when known security experts inform them of vulnerabilities. Despite the discovery of well-documented vulnerabilities, browser vendors tend to stick to their release schedules, which means that a necessary patch will not be released before the next scheduled update. However, when Guido Landi found a flaw in the current desktop Firefox software, which allows an attacker to install unauthorized software on a user's system, he chose to post the exploit code in the hope that Mozilla would react fast. By publishing the attack ...
Firefox fix due next week after attack is published
Macworld —
... , IDG News Service Online attack code has been released targeting a critical, unpatched flaw in the Firefox browser. The attack code, written by security researcher Guido Landi was published on several security sites Wednesday, sending Firefox developers scrambling to patch the issue. Until the flaw is patched, this code could be modified by attackers and used to sneak unauthorized software onto a Firefox user's machine. Mozilla developers have already worked out a fix for the vulnerability. It's slated to ship in the upcoming ...
Next Week's Firefox 3.0.8 Release Termed "High-Priority Firedrill" [OStatic]
GigaOM Network —
... A security researcher discovered that Firefox is vulnerable to remote memory corruption, enabling attackers to execute malicious (or at least very much unauthorized) code within the context of the browser. While security researchers spend countless hours searching out bugs and vulnerabilities, it's not usually the case that the offending attack finds its way into the public eye. Yesterday, however, this little exploit was published on several security sites. The ...
Next Week's Firefox 3.0.8 Release Termed "High-Priority Firedrill"
OStatic blogs —
... A security researcher discovered that Firefox is vulnerable to remote memory corruption, enabling attackers to execute malicious (or at least very much unauthorized) code within the context of the browser. While security researchers spend countless hours searching out bugs and vulnerabilities, it's not usually the case that the offending attack finds its way into the public eye. Yesterday, however, this little exploit was published on several security sites. The ...
Firefox Bug Fix on Tap For Next Week
eWeek - RSS Feeds —
With attack code for a new bug affecting Firefox users on Linux, Mac and Windows circulating, Mozilla has prepared a fix. The patch however will not be shipped until next week along with a new update for the browser. Mozilla has already patched the zero-day vulnerability in its Firefox browser uncovered by security researcher Guido Landi but users will have to wait a while to get it. Attack code for the flaw was published yesterday on numerous security sites. The code takes advantage of a XSL Parsing 'root' X M L Tag Remote Memory Corruption vulnerability, and can be used to ...


