• Moderatore

    Firefox 3.6.11 e 3.5.14

    Sono uscite le nuove versioni dei due rami sviluppati di Firefox. Le modifiche riguardano qualche problemino di sicurezza per cui vale la pena aggiornare.


  • User Attivo

    Strano,l'associazione di traduzione e sviluppo di mozilla non lo ha detto...


  • User

    @NetMassimo said:

    Sono uscite le nuove versioni dei due rami sviluppati di Firefox. Le modifiche riguardano qualche problemino di sicurezza per cui vale la pena aggiornare.
    Quale problema di sicurezza?


  • Moderatore

  • User

    @NetMassimo said:

    Su www . mozilla.org/security/known-vulnerabilities/firefox36.html#firefox3.6.11 e www . mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.14 sono elencati i problemi di sicurezza risolti.

    Impact key:

    Critical: Vulnerability can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.
    High: Vulnerability can be used to gather sensitive data from sites in other windows or inject data or code into those sites, requiring no more than normal browsing actions.
    Moderate: Vulnerabilities that would otherwise be High or Critical except they only work in uncommon non-default configurations or require the user to perform complicated and/or unlikely steps.
    Low: Minor security vulnerabilities such as Denial of Service attacks, minor data leaks, or spoofs. (Undetectable spoofs of SSL indicia would have "High" impact because those are generally used to steal sensitive data intended for other sites.)
    FIXED IN FIREFOX 3.6.12

    MFSA 2010-73 Heap buffer overflow mixing document.write and DOM insertion
    FIXED IN FIREFOX 3.6.11

    MFSA 2010-72 Insecure Diffie-Hellman key exchange
    MFSA 2010-71 Unsafe library loading vulnerabilities
    MFSA 2010-70 SSL wildcard certificate matching IP addresses
    MFSA 2010-69 Cross-site information disclosure via modal calls
    MFSA 2010-68 XSS in gopher parser when parsing hrefs
    MFSA 2010-67 Dangling pointer vulnerability in LookupGetterOrSetter
    MFSA 2010-66 Use-after-free error in nsBarProp
    MFSA 2010-65 Buffer overflow and memory corruption using document.write
    MFSA 2010-64 Miscellaneous memory safety hazards (rv:1.9.2.11/ 1.9.1.14)
    FIXED IN FIREFOX 3.6.9

    MFSA 2010-63 Information leak via XMLHttpRequest statusText
    MFSA 2010-62 Copy-and-paste or drag-and-drop into designMode document allows XSS
    MFSA 2010-61 UTF-7 XSS by overriding document charset using <object> type attribute
    MFSA 2010-59 SJOW creates scope chains ending in outer object
    MFSA 2010-58 Crash on Mac using fuzzed font in data: URL
    MFSA 2010-57 Crash and remote code execution in normalizeDocument
    MFSA 2010-56 Dangling pointer vulnerability in nsTreeContentView
    MFSA 2010-55 XUL tree removal crash and remote code execution
    MFSA 2010-54 Dangling pointer vulnerability in nsTreeSelection
    MFSA 2010-53 Heap buffer overflow in nsTextFrameUtils::TransformText
    MFSA 2010-52 Windows XP DLL loading vulnerability
    MFSA 2010-51 Dangling pointer vulnerability using DOM plugin array
    MFSA 2010-50 Frameset integer overflow vulnerability
    MFSA 2010-49 Miscellaneous memory safety hazards (rv:1.9.2.9/ 1.9.1.12)
    FIXED IN FIREFOX 3.6.8

    MFSA 2010-48 Dangling pointer crash regression from plugin parameter array fix
    FIXED IN FIREFOX 3.6.7

    MFSA 2010-47 Cross-origin data leakage from script filename in error messages
    MFSA 2010-46 Cross-domain data theft using CSS
    MFSA 2010-45 Multiple location bar spoofing vulnerabilities
    MFSA 2010-44 Characters mapped to U+FFFD in 8 bit encodings cause subsequent character to vanish
    MFSA 2010-43 Same-origin bypass using canvas context
    MFSA 2010-42 Cross-origin data disclosure via Web Workers and importScripts
    MFSA 2010-41 Remote code execution using malformed PNG image
    MFSA 2010-40 nsTreeSelection dangling pointer remote code execution vulnerability
    MFSA 2010-39 nsCSSValue::Array index integer overflow
    MFSA 2010-38 Arbitrary code execution using SJOW and fast native function
    MFSA 2010-37 Plugin parameter EnsureCachedAttrParamArrays remote code execution vulnerability
    MFSA 2010-36 Use-after-free error in NodeIterator
    MFSA 2010-35 DOM attribute cloning remote code execution vulnerability
    MFSA 2010-34 Miscellaneous memory safety hazards (rv:1.9.2.7/ 1.9.1.11)
    FIXED IN FIREFOX 3.6.4

    MFSA 2010-33 User tracking across sites using Math.random()
    MFSA 2010-32 Content-Disposition: attachment ignored if Content-Type: multipart also present
    MFSA 2010-31 focus() behavior can be used to inject or steal keystrokes
    MFSA 2010-30 Integer Overflow in XSLT Node Sorting
    MFSA 2010-29 Heap buffer overflow in nsGenericDOMDataNode::SetTextInternal
    MFSA 2010-28 Freed object reuse across plugin instances
    MFSA 2010-26 Crashes with evidence of memory corruption (rv:1.9.2.4/ 1.9.1.10)
    FIXED IN FIREFOX 3.6.3

    'MFSA 2010-25 Re-use of freed object due to scope confusion
    FIXED IN FIREFOX 3.6.2

    MFSA 2010-24 XMLDocument::load() doesn't check nsIContentPolicy
    MFSA 2010-23 Image src redirect to mailto: URL opens email editor
    MFSA 2010-22 Update NSS to support TLS renegotiation indication
    MFSA 2010-20 Chrome privilege escalation via forced URL drag and drop
    MFSA 2010-19 Dangling pointer vulnerability in nsPluginArray
    MFSA 2010-18 Dangling pointer vulnerability in nsTreeContentView
    MFSA 2010-16 Crashes with evidence of memory corruption (rv:1.9.2.2/ 1.9.1.9/ 1.9.0.19)
    MFSA 2010-15 Asynchronous Auth Prompt attaches to wrong window
    MFSA 2010-14 Browser chrome defacement via cached XUL stylesheets
    MFSA 2010-13 Content policy bypass with image preloading
    MFSA 2010-12 XSS using addEventListener and setTimeout on a wrapped object
    MFSA 2010-11 Crashes with evidence of memory corruption (rv:1.9.2.2/ 1.9.1.8/ 1.9.0.18)
    MFSA 2010-10 XSS via plugins and unprotected Location object
    MFSA 2010-09 Deleted frame reuse in multipart/x-mixed-replace image
    MFSA 2010-08 WOFF heap corruption due to integer overflow
    There was no Firefox 3.6.1 release.

    FIXED IN FIREFOX 3.6

    MFSA 2010-05 XSS hazard using SVG document and binary Content-Type
    MFSA 2010-04 XSS due to window.dialogArguments being readable cross-domain
    MFSA 2010-03 Use-after-free crash in HTML parser
    MFSA 2010-02 Web Worker Array Handling Heap Corruption Vulnerability
    MFSA 2010-01 Crashes with evidence of memory corruption (rv:1.9.1.8/ 1.9.0.18)