{"id":343,"date":"2011-09-29T14:34:08","date_gmt":"2011-09-29T13:34:08","guid":{"rendered":"http:\/\/blogs.silicontechnix.com\/?p=343"},"modified":"2011-09-29T15:12:22","modified_gmt":"2011-09-29T14:12:22","slug":"firefox-7-released-includes-updates-for-security-not-ssl-beast","status":"publish","type":"post","link":"https:\/\/blogs.silicontechnix.com\/?p=343","title":{"rendered":"Firefox 7 Released &#8211; Includes updates for Security, not SSL (BEAST)"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><strong>Firefox 7 isn&#39;t just about speed, there&#39;s also a long list of security patches. Surprisingly, a fix for the <a href=\"https:\/\/blogs.silicontechnix.com\/?p=341\">SSL BEAST<\/a> attack is not one of them.<\/strong><\/p>\n<p>Mozilla is patching it&#39;s Firefox Web browser for at least 10 vulnerabilities, seven of which are rated as being &quot;critical.&quot; Firefox 7 was released on Tuesday offering users the promised of improved performance and better memory usage.<\/p>\n<p>On the security front, the Firefox 7 release provides a critical fix for what Mozilla describes as, &quot;Miscellaneous memory safety hazards.&quot;<\/p>\n<p>&quot;Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products,&quot;<br \/>\n\tMozilla stated in its <a href=\"http:\/\/www.mozilla.org\/security\/announce\/2011\/mfsa2011-36.html\">advisory<\/a>. &quot;Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of&nbsp; these could be exploited to run arbitrary code.&quot;<\/p>\n<p style=\"text-align: justify;\">There is also a critical fix for an interesting flaw that could have been triggered by having a user hold down the &#39;Enter&#39; key. By holding <br \/>\n\tdown the key, code could potentially be installed without a user&#39;s knowledge.<\/p>\n<p>&quot;Mariusz Mlynski reported that if you could convince a user to hold down the Enter key &#8212; as part of a game or test, perhaps &#8212; a malicious <br \/>\n\tpage could pop up a download dialog where the held key would then activate the default Open action,&quot; Mozilla <a href=\"http:\/\/www.mozilla.org\/security\/announce\/2011\/mfsa2011-40.html\">warned<\/a>.<\/p>\n<p>Other critical flaws that are fixed in Firefox 7 include potentially exploitable crashes in WebGL graphics and the YARR regular expression <br \/>\n\tlibrary. Firefox 7 also provides a fix for a high impact flaw where cross-site scripting (XSS) could have been enabled via plugins.<\/p>\n<p>There is also a fix in Firefox 7 for a flaw rated as &quot;moderate&quot; that is triggered by the motion of a device. Mozilla&#39;s <a href=\"http:\/\/www.mozilla.org\/security\/announce\/2011\/mfsa2011-45.html\">advisory<\/a> noted that a recent research paper detailed how it would be possible to inferring keystrokes from device motion data on mobile devices.<\/p>\n<p>&quot;Web pages can now receive data similar to the apps studied in that paper and likely present a similar risk,&quot; Mozilla warned. &quot;We have decided to limit motion data events to the currently-active tab to prevent the possibility of background tabs attempting to decipher <br \/>\n\tkeystrokes the user is entering into the foreground tab.&quot;<\/p>\n<p><u><strong><a href=\"https:\/\/blogs.silicontechnix.com\/?p=341\">SSL BEAST <\/a><\/strong><\/u><\/p>\n<p>While Firefox 7 addresses multiple security issues, it is not taking specific aim at the recent disclosure of <a href=\"http:\/\/www.esecurityplanet.com\/browser-security\/ssl-beast-exposes-security-risk-.html\">potential SSL vulnerabilities<\/a>.&nbsp;Overall, Mozilla has <a href=\"http:\/\/blog.mozilla.com\/security\/2011\/09\/27\/attack-against-tls-protected-communications\/\">publicly noted<\/a> that they do not believe Firefox to currently be at risk from the SSL BEAST attack<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Firefox 7 isn&#39;t just about speed, there&#39;s also a long list of security patches. Surprisingly, a fix for the SSL BEAST attack is not one of them. Mozilla is patching it&#39;s Firefox Web browser for at least 10 vulnerabilities, seven of which are rated as being &quot;critical.&quot; Firefox 7 was released on Tuesday offering [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_s2mail":"yes","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[48,17,95],"tags":[161,163,62,480,143,162],"class_list":["post-343","post","type-post","status-publish","format-standard","hentry","category-browser","category-security","category-system-administration","tag-beast","tag-chrome","tag-firefox","tag-security","tag-ssl","tag-tls"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p12j6H-5x","_links":{"self":[{"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=\/wp\/v2\/posts\/343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=343"}],"version-history":[{"count":7,"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=\/wp\/v2\/posts\/343\/revisions"}],"predecessor-version":[{"id":350,"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=\/wp\/v2\/posts\/343\/revisions\/350"}],"wp:attachment":[{"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=343"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.silicontechnix.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}