<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; thunderbird</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/thunderbird//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Firefox 2.0.0.12 Security Release</title>
		<link>http://42.kaizeku.com/firefox/firefox-20012-security-release/</link>
		<comments>http://42.kaizeku.com/firefox/firefox-20012-security-release/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 15:45:48 +0000</pubDate>
		<dc:creator>chaoskaizer.myopenid.com</dc:creator>
		
		<category><![CDATA[Mozilla Firefox]]></category>

		<category><![CDATA[Web Browsers]]></category>

		<category><![CDATA[browser]]></category>

		<category><![CDATA[cve]]></category>

		<category><![CDATA[gecko]]></category>

		<category><![CDATA[javascript]]></category>

		<category><![CDATA[thunderbird]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/firefox/firefox-20012-security-release/</guid>
		<description><![CDATA[

Firefox 2.0.0.12 Security Update fixes 7 Vulnerability &#38; 3 critical patch (memory corruption, JavaScript Engine Crashes).

 Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.11) 

MFSA 2008-11

Web forgery overwrite with div overlay

Descriptions
Security researchers Emil Ljungdahl and Lars-Olof Moilanen demonstrated that, in cases where the entire contents of a page are enclosed in a &#60;div&#62; with absolute positioning, [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><a class="exturl icn-r1" href="http://www.mozilla.com/en-US/firefox/all.html"><strong>Firefox 2.0.0.12</strong></a> Security Update fixes <a class="exturl icn-r" href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.12">7 Vulnerability &amp; 3 critical patch</a> (memory corruption, <a class="exturl icn-r1" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087">JavaScript Engine Crashes</a>).<br />
<span id="more-192"></span></p>
<h2 id="firefox2.0.0.12" class="cb"> Known Vulnerabilities in Mozilla Products (Firefox 2.0.0.11) </h2>
<dl class="xoxo def">
<dt class="b1t-"><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-11.html">MFSA 2008-11</a></dt>
<dd class="b1t-">
<h3 class="title- mg-">Web forgery overwrite with div overlay</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researchers <em>Emil Ljungdahl</em> and <em>Lars-Olof Moilanen</em> demonstrated that, in cases where the entire contents of a page are enclosed in a <tt class="di">&lt;div&gt;</tt> with absolute positioning, a web forgery warning dialog won&#8217;t be displayed unless the user switches tabs away-from then back-to the forgery page.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a rel="nofollow" class="exturl icn-r1" title="Web forgery warning not shown until tab switch" href="https://bugzilla.mozilla.org/show_bug.cgi?id=408164">Web forgery warning not shown until tab switch</a>
</li>
<li><a rel="nofollow" class="exturl icn-r1" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0594">National Vulnerability Database (NVD) - CVE-2008-0594</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-10.html">MFSA 2008-10</a></dt>
<dd>
<h3 class="title- mg-">URL token stealing via stylesheet redirect</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researcher <em>Martin Straka</em> reported that <strong>Gecko-based browsers</strong> update the <tt class="di">.href</tt> property of stylesheet DOM nodes to reflect the final URI of the stylesheet after following any 302 redirects (much as the <tt class="di">document.location</tt> property is updated). This differs from other browsers and could potentially reveal sensitive URL parameters, such as those used by Single-signon sytems, to scripts on the page.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Stylesheet href property shows redirected URL unlike other browsers" href="https://bugzilla.mozilla.org/show_bug.cgi?id=397427">Stylesheet href property shows redirected URL unlike other browsers</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0593">National Vulnerability Database (NVD) - CVE-2008-0593</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 low" href="http://www.mozilla.org/security/announce/2008/mfsa2008-09.html">MFSA 2008-09</a></dt>
<dd>
<h3 class="title- mg-">Mishandling of locally-saved plain text files</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributor <em>oo.rio.oo</em> demonstrated that once a file with <tt class="di">Content-Disposition: attachment</tt> and (improper) <tt class="di">Content-Type: plain/text</tt> is saved locally, the browser would no longer open local files with <tt class="di">.txt</tt> extensions for viewing, but would rather prompt the user to save the file.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="plain text txt file viewing capability lost after having downloaded a txt file" href="https://bugzilla.mozilla.org/show_bug.cgi?id=387258">plain text txt file viewing capability lost after having downloaded a txt file with content-disposition: attachment and content-type: plain/text</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0592">National Vulnerability Database (NVD) - CVE-2008-0592</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-08.html">MFSA 2008-08</a></dt>
<dd>
<h3 class="title- mg-">File action dialog tampering</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researcher <em>Michal Zalewski</em> demonstrated that timer-enabled security dialogs can be subverted by attackers using JavaScript to change the window focus. Zalewski showed that a user could be tricked into confirming a security dialog of this type by bringing the dialog back into focus right before a user clicked in a predictable time and place.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="file action dialog controls vulnerable to refocus race" href="https://bugzilla.mozilla.org/show_bug.cgi?id=376473">file action dialog controls vulnerable to refocus race</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0591">National Vulnerability Database (NVD) - CVE-2008-0591</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-06.html">MFSA 2008-06</a></dt>
<dd>
<h3 class="title- mg-">Web browsing history and forward navigation stealing</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributor <em>David Bloom</em> reported a vulnerability in the way images are treated by the browser when a user leaves a page which utilizes <tt class="di">designMode</tt> frames. The reported issue can be used to steal a user&#8217;s navigation history, forward navigation information, and crash the user&#8217;s browser. The crash showed evidence of memory corruption and might be exploitable to run arbitrary code.<br />
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Vulnerability allows script to see where user is headed, sniff history, and crash nsDocShell::Destroy() the browser too" href="https://bugzilla.mozilla.org/show_bug.cgi?id=400556">Vulnerability allows script to see where user is headed, sniff history, and crash [@ nsDocShell::Destroy()] the browser too</a></li>
<li>
<a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0419">National Vulnerability Database (NVD) - CVE-2008-0419</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 high" href="http://www.mozilla.org/security/announce/2008/mfsa2008-05.html">MFSA 2008-05</a></dt>
<dd>
<h3 class="title- mg-">Directory traversal via chrome: URI</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p><em>Gerry Eisenhaur</em> reported the chrome: URI scheme improperly allowed directory traversal that could be used to load JavaScript, images, and stylesheets from local files in known locations. This traversal was possible only when the browser had installed add-ons which used &#8220;flat&#8221; packaging rather than the more popular .jar packaging, and the attacker would need to target that specific add-on.</p>
<p>Mozilla researcher <strong>moz_bug_r_a4</strong> reported that this vulnerability could be used to steal the contents of the browser&#8217;s <tt class="di">sessionstore.js</tt> file, which contains session cookie data and information about currently open web pages.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Allows to steal data from sessionstore.js" href="https://bugzilla.mozilla.org/show_bug.cgi?id=413451">Allows to steal data from sessionstore.js</a></li>
<li><a class="exturl icn-r1" title="chrome directory traversal (local disk access via flat addons)" href="https://bugzilla.mozilla.org/show_bug.cgi?id=413250">chrome directory traversal (local disk access via &#8220;flat&#8221; addons)</a></li>
<li><a class="exturl icn-r1" title="list of flat packaged add-ons" href="https://bugzilla.mozilla.org/attachment.cgi?id=300181">list of &#8220;flat&#8221; packaged add-ons</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0418">National Vulnerability Database (NVD) - CVE-2008-0418</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-04.html">MFSA 2008-04</a></dt>
<dd>
<h3 class="title- mg-">Stored password corruption</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla developer <em>Justin Dolske</em> discovered that malicious sites, upon a user saving his or her password, could inject newlines into Firefox&#8217;s password store and corrupt saved passwords for other sites.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="Content can corrupt stored passwords by injecting line breaks" href="https://bugzilla.mozilla.org/show_bug.cgi?id=394610">Content can corrupt stored passwords by injecting line breaks</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0417">National Vulnerability Database (NVD) - CVE-2008-0417</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-03.html">MFSA 2008-03</a></dt>
<dd>
<h3 class="title- mg-">Privilege escalation, XSS, Remote Code Execution</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla contributors <strong>moz_bug_r_a4</strong> and <em>Boris Zbarsky</em> submitted a series of vulnerabilities which allow scripts from page content to escape from its sandboxed context and/or run with chrome privileges. An additional vulnerability reported by <tt class="di">moz_bug_r_a4</tt> demonstrated that the <tt class="di">XMLDocument.load()</tt> function can be used to inject script into another site, violating the browser&#8217;s same-origin policy.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="List of JavaScript privilege escalation bugs" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=386695,393761,393762,399298,407289,372075,363597">List of JavaScript privilege escalation bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0415">National Vulnerability Database (NVD) - CVE-2008-0415</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 moderate" href="http://www.mozilla.org/security/announce/2008/mfsa2008-02.html">MFSA 2008-02</a></dt>
<dd>
<h3 class="title- mg-">Multiple file input focus stealing vulnerabilities</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Security researchers <em>hong</em> and <em>Gregory Fleisher</em> each reported a variant on earlier reported bugs regarding focus shifting in file input controls. Their variants used file input controls nested inside <tt class="di">&lt;label&gt;</tt> tags to take advantage of automatic focus shifting into the file input field noted on the Hacker WebZine. As with the earlier reported issues this issue could be used to force a user to upload arbitrary files assuming the attacker knows the full path and name of the file.</p>
<p>These bugs are variations on earlier problems reported by <em>Charles McAuley</em> and <em>Michal Zalewski</em> which were fixed in <strong>Firefox 2.0.0.4</strong>, as well as an issue reported by hong which was fixed in <strong>Firefox 2.0.0.8</strong>.<br />
Gregory Fleisher also submitted a series of demonstrations of different ways to lure a user to place focus into the file input control manually. These demonstrations included &#8220;focus spoofing&#8221; by selectively capturing keystrokes and placing the captured characters where the user thinks the focus should be.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="List Focus shifting bugs" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=404451,408034,404391,405299">List of Focus shifting bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0414">National Vulnerability Database (NVD) - CVE-2008-0414</a></li>
</ul>
</div>
</dd>
<dt><a rev="site:mozilla" title="Mozilla Foundation Security Advisory" class="exturl icn-r1 critical" href="http://www.mozilla.org/security/announce/2008/mfsa2008-01.html">MFSA 2008-01</a></dt>
<dd>
<h3 class="title- mg-">Crashes with evidence of memory corruption (rv:1.8.1.12)</h3>
<div class="dn">
<h4 class="mgt b1s b1b b1c-gray">Descriptions</h4>
<p>Mozilla developers identified and fixed several stability bugs in the browser engine used in Firefox 2.0.0.12 and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code.</p>
<p class="notice">Thunderbird shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail. This is not the default setting and we strongly discourage users from running JavaScript in mail. Without further investigation we cannot rule out the possibility that for some of these an attacker might be able to prepare memory for exploitation through some means other than JavaScript such as large images.</p>
<h4 class="mgt b1s b1b b1c-gray">References</h4>
<ul>
<li><a class="exturl icn-r1" title="JavaScript Engine Crashes" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=407720,390597,373344,398085,406572,391028,406036,402087">List of JavaScript Engine Crashes</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0413">National Vulnerability Database (NVD) - CVE-2008-0413</a></li>
<li><a class="exturl icn-r1" title="Browser Crashes" href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=398088,393141,364801,346405,396613,394337,406290">List of Browser Crashes Bugs</a></li>
<li><a class="exturl icn-r1" rel="nofollow" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0412">National Vulnerability Database (NVD) - CVE-2008-0412</a></li>
</ul>
</div>
</dd>
</dl>
<h2 class="cb">Thunderbird Security Release</h2>
<p>Thunderbird 2.0.0.12 is schedule to be release on <a href="http://wiki.mozilla.org/Releases/Thunderbird_2.0.0.12">February 28</a>. </p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r1" href="http://www.mozilla.com/en-US/firefox/all.html">Download Firefox 2.0.0.12</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/firefox/firefox-20012-security-release/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
