作者KyleTso (负けないで)
看板Browsers
标题[-Fx-] Mozilla Firefox 3.0 Vulnerability
时间Fri Jun 20 15:28:35 2008
http://wiki.moztw.org/index.php/Firefox_FAQ ▏▎▍▌▋▊ Firefox FAQ
───────────────────────────────────────
http://dvlabs.tippingpoint.com/blog/2008/06/18/vulnerability-in-mozilla-
firefox-30/
http://0rz.tw/074hp=
不想看英文的可以直接看下面重点
Mozilla Firefox 3.0 Vulnerability
By Zero Day Initiative
A number of people who monitor our Zero Day Initiative's Upcoming Advisories
page noticed yesterday that we reported a vulnerability to Mozilla
(ZDI-CAN-349). Taking into account the coincidental timing of the Firefox
3.0 release, many are asking us if this is the first reported critical
vulnerability in the latest version of the popular open source browser.
What we can confirm is that about
five hours after the official release of
Firefox 3.0 on June 17th, our Zero Day Initiative program received a critical
vulnerability
affecting Firefox 3.0 as well as prior versions of Firefox
2.0.x. We verified the vulnerability in our lab, acquired it from the
researcher, then promptly reported the vulnerability to the Mozilla security
team shortly after. Successful exploitation of the vulnerability could allow
an attacker to execute arbitrary code. Not unlike most browser based
vulnerabilities that we see these days,
user interaction is required such as
clicking on a link in email or visiting a malicious web page.
While
Mozilla is working on a fix, we wont be divulging anything else until a
patch is available, adhering to our vulnerability disclosure policy. Once
the issue is patched, we'll be publishing an advisory here. Working with
Mozilla on past security issues, we've found them to have a good track record
and expect a reasonable turnaround on this issue as well.
---
重点就是
1. Fx3正式版在release之後的五个小时就被人匿名通知此zero day vulnerability
2. 这个漏洞要点恶意连结或是浏览恶意网站才会中奖
3. Fx2也有这个漏洞,不知道为什麽匿名通知者到现在才公布
4. Mozilla已经在着手修复这个漏洞
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 140.115.221.3
1F:→ chris:请问什麽是zero day vulnerability 呀?@@|| 06/20 15:40
2F:推 karst10607:喔喔~ 06/20 15:40
3F:推 karst10607:到时候可能会推出3.0.0.1更新 ~"~还是官网会放新版本.. 06/20 15:42
4F:推 josesun:zero day 就是在这个漏洞公布之前或公布後很短的时间内就 06/20 15:44
5F:→ taco20:微软出手了 06/20 15:44
6F:→ josesun:已经被人拿来利用的意思。另,会出 3.0.0.1 06/20 15:44
7F:推 ileadu:会慢点才公布 就是不想被利用这一漏洞 06/20 16:33