Security experts have warned of a potentially serious flaw in the way that Mozilla's Firefox browser handles JavaScript
A flaw in Firefox could allow attackers to take control of a system through a specially crafted web page

JavaScript flaw threatens Firefox

Unpatched vulnerability could allow remote code execution

Written by Shaun Nichols in California

Security experts have warned of a potentially serious flaw in the way that Mozilla's Firefox browser handles JavaScript.

Two independent researchers outlined the vulnerability in a presentation over the weekend at the ToorCon hacker conference.

The pair claimed that the vulnerability could allow attackers to take control of a system through a specially crafted web page.

Mozilla security chief Window Snyder said in a blog posting on the Mozilla developer site that it is possible to force browser crashes using the vulnerability. 

Snyder did not confirm that the flaw could be exploited to allow remote code execution.

The vulnerability affects the 'chrome context' component of Firefox, according to Eric Sites, vice president of research and development at security vendor Sunbelt Software.

"Chrome context provides certain trusted code such as JavaScript with full access to Firefox's resources," Sites told vnunet.com.

"If a script gets into that chrome context, then it's just like you copied that script to your computer and ran it with no restrictions whatsoever." 

Although there are no known exploits of the vulnerability, Sites warned that the flaw could be included in the WebAttacker toolkit which provides malware authors with an automated tool to craft new worms and viruses.

"We have already seen [WebAttacker] JavaScript exploits targeted at Firefox, so I am sure these guys will be picking up these scripts and implementing them in WebAttacker pretty quickly," he said.

Sites compared the impact of the Firefox vulnerability to the ActiveX software zero-day exploits that hit Microsoft's Internet Explorer in the past week.

In two separate incidents, attackers used an unpatched vulnerability in Explorer to execute arbitrary code. Microsoft rushed out a patch for the VML flaws last week, but the ActiveX flaw remains unpatched. 

The open source status of Firefox allows its developer community to quickly create a patch once a solution has been found, but Sites warned that the vulnerability is still "pretty dangerous" to users.

"One thing that Mozilla has going for it is an interesting framework that allows for sending out updates very quickly," he said.

Tags:

Further reading

Related articles

Mozilla issues 'critical' Firefox fixes

Update addresses a number of security issues   More...

Attackers feast on Real Player flaw

Real promises to patch hole as soon as possible   More...

vnunet.com analysis: Browser wars changing security game

Variety and competition bring new protections and new threats   More...

Apple QuickTime exploit goes wild

Streaming media flaw used to push malware   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement