Firefox spoofing bug uncovered

Opinion
Jan 7, 20083 mins

* Patches from rPath, Debian, Mandriva, others * Facebook's "Secret Crush" malicious widget tricks users * Office 2003 SP3 blocks old file formats, and other interesting reading

Firefox continues to have potential security flaws uncovered, this time a spoofing bug that could allow an attacker to steal authentication information from “trusted” sites. Also, Microsoft is prepping two patches — one critical — for this week’s Patch Tuesday. And in a sign that Facebook is becoming a popular target for hackers, a new “Secret Crush” widget entices users to download spyware.

Today’s bug patches and security alerts:

Firefox hit with spoofing bug

A serious flaw in how Firefox handles logons could be used by identity thieves to dupe users into disclosing passwords, a noted security researcher said Wednesday. According to Raff, Firefox 2.0.0.11 — Mozilla’s most current version — fails to sanitize single quotation marks and spaces in what’s called the “Realm” value of an authentication header. “This makes it possible for an attacker to create a specially crafted Realm value which will look as if the authentication dialog came from a trusted site,” said Raff. Computerworld, 01/03/08.

**********

Microsoft readies for two Windows security updates

Microsoft plans to issue two security updates for its Windows operating system products next Tuesday as part of its regular software patch cycle. One of the updates is considered critical for Windows Vista and XP users because the flaw it fixes could be used by attackers to install unauthorized software on a victim’s computer. This update is rated important for Windows Server 2003 users and considered moderate for Windows 2000 users. IDG News Service, 01/03/08.

Microsoft advance advisory

**********

Five new patches from rPath:

cups (buffer overflow, code execution)

tetex (buffer overflow, code execution)

libexif (multiple flaws)

tshark/wireshark (denial of service)

dovecot (multiple flaws)

**********

Eight new updates from Debian:

util-linux (privilege escalation)

loop-aes-utils (programming error, privilege escalation)

eggdrop (buffer overflow, code execution)

Tomcat 5.5 (multiple flaws)

wireshark (multiple flaws)

maradns (programming error, denial of service)

PHP5 (multiple flaws)

tcpreen (buffer overflow, denial of service)

**********

Two new fixes from Mandriva:

Wirehshark (multiple flaws)

Squid (denial of service)

**********

Latest malware news:

Facebook’s “Secret Crush” malicious widget tricks users

A “widget” application used on the Facebook social network site promises to tell you who has a secret crush on you, but instead tries to trick you into downloading spyware. Network World, 01/03/08.

Symantec Security Response blog: I’ve Got a Crush on You

A Wi-Fi virus outbreak? Researchers say it’s possible

If criminals were to target unsecured wireless routers, they could create an attack that could piggyback across thousands of Wi-Fi networks in urban areas like Chicago or New York City, according to researchers at Indiana University. IDG News Service, 01/04/08.

‘Ransomware’ extorts payment with phone call

New “ransomware” that locks up a person’s PC and demands $35 to return control to its user is on the prowl, a security researcher said this week. Computerworld, 01/02/08.

**********

From interesting reading department:

Office 2003 SP3 blocks old file formats

Microsoft deliberately broke access to older files, including many generated by its own products, to step up security with the newest Office 2003 service pack, a company evangelist said yesterday. Computerworld, 01/03/08.

Read the Microsoft workaround advisory

CA’s Web site hacked by malware authors

Part of security software vendor CA’s Web site was cracked earlier this week and was redirecting visitors to a malicious Web site hosted in China. IDG News Service, 01/04/08.

QuickBooks can still delete data, Intuit warns

Financial software maker Intuit warned Mac users that a bug that could cause its small business accounting to erase files from the desktop arbitrarily is still present, at least from some public hot spot locations, according to a posting on the company’s support discussion forums. MacWorld, 01/03/08.