<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Eternal Code &#187; security researcher</title>
	<atom:link href="http://www.eternalcode.com/tag/security-researcher/feed" rel="self" type="application/rss+xml" />
	<link>http://www.eternalcode.com</link>
	<description>Horrendously left-wing news from across the Internets</description>
	<lastBuildDate>Sat, 26 Nov 2011 09:54:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Mozilla confirms 0-day Firefox flaw</title>
		<link>http://www.eternalcode.com/mozilla-confirms-0-day-firefox-flaw/</link>
		<comments>http://www.eternalcode.com/mozilla-confirms-0-day-firefox-flaw/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 15:24:39 +0000</pubDate>
		<dc:creator>Nexus</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[0 day]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Evgeny Legerov]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[flaw]]></category>
		<category><![CDATA[free software]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[mozilla foundation]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[security researcher]]></category>
		<category><![CDATA[thunderbird]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web browser]]></category>

		<guid isPermaLink="false">http://www.eternalcode.com/?p=1704</guid>
		<description><![CDATA[[via bit-tech.net] The Mozilla Foundation has confirmed the existence of a critical zero-day vulnerability in its popular Firefox web-browser &#8211; but says a fix won&#8217;t arrive before the end of the month. Posting on its official &#8230; <a class="more-link" href="http://www.eternalcode.com/mozilla-confirms-0-day-firefox-flaw/">More<span class="meta-nav">&#8594;</span></a><p>Link to article: <a href="http://www.eternalcode.com/mozilla-confirms-0-day-firefox-flaw/">Mozilla confirms 0-day Firefox flaw</a></p>
]]></description>
			<content:encoded><![CDATA[<p><em>[via <a href="http://www.bit-tech.net/news/bits/2010/03/22/moz-confirms-0-day-firefox-flaw/1">bit-tech.net</a>]</em></p>
<p><a href="http://www.eternalcode.com/wordpress/wp-content/uploads/2010/03/article_img_firefox.jpg"><img style=' float: right; padding: 4px; margin: 0 0 2px 7px;'  src="http://www.eternalcode.com/wordpress/wp-content/uploads/2010/03/article_img_firefox-200x166.jpg" alt="" title="article_img_firefox" width="200" height="166" class="alignright size-thumbnail wp-image-1703" /></a></p>
<p>The Mozilla Foundation has confirmed the existence of a critical  zero-day vulnerability in its popular Firefox web-browser &#8211; but says a  fix won&#8217;t arrive before the end of the month.</p>
<p>Posting on its official <a href="http://blog.mozilla.com/security/2010/03/18/update-on-secunia-advisory-sa38608/" target="_blank">security blog</a>, the Foundation confirmed a  vulnerability which it has &#8220;<em>determined to be critical and [which]  could result in remote code execution by an attacker.</em>&#8221;</p>
<p>The good news?  The Foundation has already developed a fix, which is  currently undergoing quality assurance testing prior to a general  roll-out.  The bad news?  That roll-out isn&#8217;t due for at least a week,  potentially leaving Firefox users vulnerable to attack.</p>
<p>The bug, originally discovered by security researcher Evgeny Legerov  last month, was posted publicly but without the code required to carry  out an attack.  However, it appears that Legerov was reticent to provide  detailed information to Mozilla &#8211; with <a href="http://www.arnnet.com.au/article/340291/mozilla_confirms_critical_firefox_bug/?rid=-100" target="_blank">ARN</a> pointing to a now-deleted post on the  researcher&#8217;s blog admitting to &#8220;<em>ignoring e-mails</em>&#8221; from the  foundation and refusing to provide enough detail for the Foundation to  reproduce the exploit.</p>
<p>Thankfully, the Foundation says that Legerov has now provided &#8220;<em>sufficient  details to reproduce and analyse the issue,</em>&#8221; meaning the flaw can  be fixed and the patch prepared for a planned 30th of March roll-out.   Those who are itching for a fix and don&#8217;t mind running code that isn&#8217;t  as well tested as a standard release are advised to grab a copy of the <a href="https://ftp.mozilla.org/pub/mozilla.org/firefox/nightly/3.6.2-candidates/build3/" target="_blank">nightly build</a> of Firefox 3.6.2, which contains the  patch to prevent the exploit from running.</p>
<p>Link to article: <a href="http://www.eternalcode.com/mozilla-confirms-0-day-firefox-flaw/">Mozilla confirms 0-day Firefox flaw</a></p>
Share:<a rel="nofollow" target="_blank"  href="mailto:?subject=Mozilla%20confirms%200-day%20Firefox%20flaw&amp;body=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/email_link.png" class="sociable-img sociable-hovers" title="email" alt="email" /></a><a rel="nofollow" target="_blank"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F&amp;title=Mozilla%20confirms%200-day%20Firefox%20flaw" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/stumbleupon.png" class="sociable-img sociable-hovers" title="StumbleUpon" alt="StumbleUpon" /></a><a rel="nofollow" target="_blank"  href="http://twitter.com/home?status=Mozilla%20confirms%200-day%20Firefox%20flaw%20-%20http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/twitter.png" class="sociable-img sociable-hovers" title="Twitter" alt="Twitter" /></a><a rel="nofollow" target="_blank"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F&amp;title=Mozilla%20confirms%200-day%20Firefox%20flaw&amp;bodytext=%5Bvia%20bit-tech.net%5D%0D%0A%0D%0A%0D%0A%0D%0AThe%20Mozilla%20Foundation%20has%20confirmed%20the%20existence%20of%20a%20critical%20%20zero-day%20vulnerability%20in%20its%20popular%20Firefox%20web-browser%20-%20but%20says%20a%20%20fix%20won%27t%20arrive%20before%20the%20end%20of%20the%20month.%0D%0A%0D%0APosting%20on%20its%20official%20security%20blog" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/digg.png" class="sociable-img sociable-hovers" title="Digg" alt="Digg" /></a><a rel="nofollow" target="_blank"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F&amp;title=Mozilla%20confirms%200-day%20Firefox%20flaw&amp;notes=%5Bvia%20bit-tech.net%5D%0D%0A%0D%0A%0D%0A%0D%0AThe%20Mozilla%20Foundation%20has%20confirmed%20the%20existence%20of%20a%20critical%20%20zero-day%20vulnerability%20in%20its%20popular%20Firefox%20web-browser%20-%20but%20says%20a%20%20fix%20won%27t%20arrive%20before%20the%20end%20of%20the%20month.%0D%0A%0D%0APosting%20on%20its%20official%20security%20blog" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/delicious.png" class="sociable-img sociable-hovers" title="del.icio.us" alt="del.icio.us" /></a><a rel="nofollow" target="_blank"  href="http://slashdot.org/bookmark.pl?title=Mozilla%20confirms%200-day%20Firefox%20flaw&amp;url=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/slashdot.png" class="sociable-img sociable-hovers" title="Slashdot" alt="Slashdot" /></a><a rel="nofollow" target="_blank"  href="http://identi.ca/notice/new?status_textarea=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/identica.png" class="sociable-img sociable-hovers" title="Identi.ca" alt="Identi.ca" /></a><a rel="nofollow" target="_blank"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F&amp;title=Mozilla%20confirms%200-day%20Firefox%20flaw" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/reddit.png" class="sociable-img sociable-hovers" title="Reddit" alt="Reddit" /></a><a rel="nofollow" target="_blank"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F&amp;t=Mozilla%20confirms%200-day%20Firefox%20flaw" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/facebook.png" class="sociable-img sociable-hovers" title="Facebook" alt="Facebook" /></a><a rel="nofollow" target="_blank"  href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F&amp;t=Mozilla%20confirms%200-day%20Firefox%20flaw" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/myspace.png" class="sociable-img sociable-hovers" title="MySpace" alt="MySpace" /></a><a rel="nofollow" target="_blank"  href="http://technorati.com/faves?add=http%3A%2F%2Fwww.eternalcode.com%2Fmozilla-confirms-0-day-firefox-flaw%2F" ><img src="http://www.eternalcode.com/wordpress/wp-content/plugins/sociable-30/images/default/16/technorati.png" class="sociable-img sociable-hovers" title="Technorati" alt="Technorati" /></a><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.eternalcode.com/mozilla-confirms-0-day-firefox-flaw/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

