Latest Comments
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
Web

Firefox, Opera image file flaw may permit attackers to grab users' web history

  • Email a Friend
  • Print Page
Firefox, Opera image file flaw may permit attackers to grab users' web history
By Jim Carr
Feb 21, 2008 9:52 AM
Tags: "firefox" | "opera" | "opera | flaw" | "firefox | and | opera"
The vulnerability is caused by the manner in which the two browsers handle a bitmap image file, according to a warning posted by Polish researcher Gynvael Coldwind of Vexillium.org. Coldwind also posted a video illustrating the problem.

According to Coldwind, an attacker can create a malicious bitmap file that extracts information from the browsers' memory. Some of the stolen data is randomly collected, but the attack also could collect valuable data, the advisory noted.

The harvested data contains various information, including parts of other websites, users' favourites and history, and other information," Coldwind said on Vexillium.org.

An attacker can capture the data using the "canvas" HTML tag supported by the two browsers, the advisory explained. Then, via JavaScript, the information can be sent to a remote server.

"This has been tested [and] a proof-of-concept exploit has been created," Coldwind said. However, he added that the exploit has not yet been released.

The vulnerability could also cause Firefox to crash. The flaw affects Firefox 2.0.0.11 and previous versions, as well as the beta version of Opera 9.50.

"Other browsers – [such as] Apple Safari – contain vulnerable BMP handling code," Coldwind noted in his report. "But since there is no way of acquiring the image data, it doesn't pose a serious threat. Then again, maybe the attacker could convince the user to do a screenshot and send it to [him].”

Coldwind said the Apple Safari browser "has a similar problem with certain GIF files."

In its advisory, US-CERT encouraged Mozilla Firefox users to upgrade to Firefox 2.0.0.12 and Opera users to upgrade to Opera 9.25.>

Window Snyder, the Mozilla Foundation's chief security officer, told SCMagazineUS.com that the problem has been corrected in 2.00.12. Mozilla recommends that users remaining on previous versions of Firefox disable JavaScript until they upgrade to the latest version. A Mozilla security advisory (2008-07) describes the issue.

Opera Software did not respond to SCMagazineUS.com's request for comment.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers