Security experts have warned of a potentially serious flaw in the way that Mozilla's Firefox browser handles JavaScript
A flaw in Firefox could allow attackers to take control of a system through a specially crafted web page

JavaScript flaw threatens Firefox

Unpatched vulnerability could allow remote code execution

Shaun Nichols in California

Security experts have warned of a potentially serious flaw in the way that Mozilla's Firefox browser handles JavaScript.

Two independent researchers outlined the vulnerability in a presentation over the weekend at the ToorCon hacker conference.

Advertisement

The pair claimed that the vulnerability could allow attackers to take control of a system through a specially crafted web page.

Mozilla security chief Window Snyder said in a blog posting on the Mozilla developer site that it is possible to force browser crashes using the vulnerability. 

Snyder did not confirm that the flaw could be exploited to allow remote code execution.

The vulnerability affects the 'chrome context' component of Firefox, according to Eric Sites, vice president of research and development at security vendor Sunbelt Software.

"Chrome context provides certain trusted code such as JavaScript with full access to Firefox's resources," Sites told vnunet.com.

"If a script gets into that chrome context, then it's just like you copied that script to your computer and ran it with no restrictions whatsoever." 

Although there are no known exploits of the vulnerability, Sites warned that the flaw could be included in the WebAttacker toolkit which provides malware authors with an automated tool to craft new worms and viruses.

"We have already seen [WebAttacker] JavaScript exploits targeted at Firefox, so I am sure these guys will be picking up these scripts and implementing them in WebAttacker pretty quickly," he said.

Sites compared the impact of the Firefox vulnerability to the ActiveX software zero-day exploits that hit Microsoft's Internet Explorer in the past week.

In two separate incidents, attackers used an unpatched vulnerability in Explorer to execute arbitrary code. Microsoft rushed out a patch for the VML flaws last week, but the ActiveX flaw remains unpatched. 

The open source status of Firefox allows its developer community to quickly create a patch once a solution has been found, but Sites warned that the vulnerability is still "pretty dangerous" to users.

"One thing that Mozilla has going for it is an interesting framework that allows for sending out updates very quickly," he said.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

old computer

Government honours veterans of Bletchley Park at last

Surviving veterans of the code-breaking facility to receive badge of...

Motorola MC55 Enterprise Digital Assistant

Review: Motorola MC55 Enterprise Digital Assistant

A rugged Windows Mobile device for mobile workers

BT

BT promises 1.5m fibre connections by summer 2010

Telco begins major rollout in 69 locations across the UK

Primary Navigation