|
|
|
Update False Security Advisory from Mozilla |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : Author SecurityReason In last week, the Mozilla team released a new security notes for Firefox. We were able to prove that one note was falsified. In June this year, our team published a security advisory about libc. We had indications that other projects software also are affected. At the end of September, the Google Chrome Team, gave a security note about this problem. http googlechromereleases.blogspot.com 2009 09 stable-channel-update_30.html They met with criticism because of slow patching this issue. However, the Firefox developers have decided to avoid bad comments. They Released a note MFSA 2009-59 - http www.mozilla.org security announce 2009 mfsa2009-59.html Firefox team maintains that the flaw was published, detected by the Secunia Research Team. It would not be any problem in that if the PoC Proof of Concept was available since June. Many months ignoring the vulnerability contributed to the exposure of millions Firefox users giving potential attackers full control over their computer. To the confusion, officially acknowledged a portal Secunia.com. An interesting element is the lack of use of the module name dtoa in which the error was detected. Link to a false note http www.mozilla.org security announce 2009 mfsa2009-59.html Link to PoC http securityreason.com achievement_securityalert 63 Below there is source code of changes that were made for Security Advisory MFSA 2009-59 http bonsai.mozilla.org cvsview2.cgi diff_mode context whitespace_mode show file jsdtoa.c branch root cvsroot subdir mozilla js src command DIFF_FRAMESET rev1 3.41 rev2 3.42 Here we present fix for libc library http www.openbsd.org cgi-bin cvsweb src lib libc gdtoa misc.c annotate 1.2 More details http www.security-database.com detail.php alert CVE-2009-1563 - informations about Vulnerability, reference in Bugzilla http bonsai.mozilla.org cvslog.cgi file mozilla js src jsdtoa.c rev HEAD mark 3.43 - informations about fix from Bugzilla number 516862, related to Secunia Research Team. At the end of this news we inform that we published new advisory about vulnerabilities in libc for BSD Operating Systems Multiple Vendors libc gdtoa printf 3 Array Overrun . A Array Overrun vulnerability has been identified in new gdtoa implementation in libc library... http securityreason.com achievement_securityalert 69 Update Mozilla Team updated the Mozilla Foundation Security Advisory 2009-59 adding note The underlying flaw in the dtoa routines used by Mozilla appears to be essentially the same as that reported against the libc gdtoa routine by Maksymilian Arciemowicz CVE-2009-0689 Secunia also updated their advisory http secunia.com advisories 36711 2 adding note 1 Reported in libc by Maksymilian Arciemowicz of SecurityReason.
Les mots clés de la revue de presse pour cet article : security advisory mozilla Les videos sur SecuObs pour les mots clés : security Les mots clés pour les articles publiés sur SecuObs : security Les éléments de la revue Twitter pour les mots clé : security advisory
Les derniers articles du site "SecurityReason IT News" :
- Multiple Vendors libc fnmatch 3 DoS - PHP 5.3.3 Null Pointer Dereference - vsftpd flaw could disable wide range of servers - GNU libc Multiple Vulnerabilities - Apache Insecure mod_rewrite PCRE Resource Exhaustion - PHP 5.3.3 Null Pointer Deference - New issues in libc glob 3 with PoC for ftpd servers - Race Condition in FreeBSD 8.1 7.3 with PoC - libopie __readrec off-by one FreeBSD ftpd remote PoC - Sun Solaris 10 Multiple Vulnerabilities
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|