8 ms·
Mozilla fixes Firefox zero-day actively exploited in attacks
- statusfailed 2y agoSeems bad. "An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild." See: - NVD page for CVE-2024-9680: https://nvd.nist.gov/vuln/detail/CVE-2024-9680 https://nvd.nist.gov/vuln/detail/CVE-2024-9680 - Mozilla security advisory: https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-5...
- deleted 2y ago[deleted]
- btdmaster 2y agoTicket in Tor Browser: https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/43201 https://gitlab.torproject.org/tpo/applications/tor-browser/-... It seems to be JavaScript-free from the description, which makes it even scarier. Imagine the libwebp decoder bug except embedded media blocking doesn't really work (who blocks CSS?).
- mrob 2y agoI block CSS animations: https://news.ycombinator.com/item?id=33223080 https://news.ycombinator.com/item?id=33223080 I'd be interested to know if it's sufficient to avoid this recent vulnerability. Either way, it confirms my opinion that UI animations are an anti-feature.
- deleted 2y ago[deleted]
- schiffern 2y agoAs a uBlock Origin filter (paste in Settings > My Filters): ! No CSS animations ##*,::before,::after:style(transition:none !important;animation-delay:0ms !important;animation-duration:0ms !important) ! No CSS animations (different method) ##*,::before,::after:style(animation-timing-function:step-start !important;transition-timing-function:step-start !important) There's other (often perf heavy) CSS clutter that's nice to get rid of: ! No image filters ##*,::before,::after:style(filter:none !important) ! No text-shadow ##*,::before,::after:style(text-shadow:none !important) ! No box-shadow ##*,::before,::after:style(box-shadow:none !important) ! No rounded corners ##*,::before,::after:style(border-radius:0px !important) No rounded corners is fun. You realize many loading spinners are actually CSS rounded corners! Youtube becomes almost unrecognizable — mercifully — especially if you also revert the new TikTok-inspired font: ! Un-bold Youtube youtube.com##*:style(font-weight:400 !important)
- krackers 2y agoFirefox doesn't seem to support css animation-timeline, I think this refers to the JS AnimationTimeline API? In that case "dom.animations-api.timelines.enabled" flag should control it.
- tomrittervg 2y agoThe vulnerability did require JavaScript to trigger. I think it would be a labor of love and craftsmanship to exploit a content process today without using JavaScript.
- jjuran 2y ago> The vulnerability did require JavaScript to trigger. Can you back this up with a citation?
- a_vanderbilt 2y agoHe works (or recently worked) for Mozilla on security-related projects. The code commit fixing the issue was isolated to the /dom/ directory in the source tree, and Firefox does not support CSS Animation Timelines. The Animation Timelines code is not directly accessed by web devs, and it appears the only way to execute that code is via the JS API for Animation Timelines. I'm not a web security expert, but the signs seem to point to him being correct. Once again, JS proves to be a security risk.
- tempaccount420 2y agoIs this karma for dropping Rust? (please don't explain how Rust actually wouldn't fix this)
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- okasaki 2y agoIt references "Bug 1923344" but when I click the link I get "You are not authorized to access bug 1923344."
- Malidir 2y agoWould Rust and it's memory safety stuff have prevented this?
- Squeeze2664 2y agoIn some sense, yes. Use-after-free is impossible in safe Rust (if you don't use the unsafe keyword)
- xwolfi 2y agoJava too !
- bubblesnort 2y agoAnd don't forget Ada.
- Yoric 2y agoAnd OCaml or Haskell :)
- sph 2y agoWhy go fancy? Even Python saves you from use-after-free.
- Yoric 2y agoCome on, I had to outbid Ada somehow :) For what it's worth, Python was also considered at some point for use in the Firefox codebase. I don't remember the rationale for not adopting it, but I think the idea was "we all like Python, but we already have one messy language (JavaScript), let's not make it two".
- jeltz 2y agoBrainfuck too!
- yencabulator 2y ago
- loopdoend 2y agoFixed many months ago just being made public now, according to the bug tracker. Why a 7 month delay?
- gpvos 2y agoCitation needed.
- Brybry 2y agoI didn't get the ESR 128.3.1 update until yesterday.
- pixelesque 2y agoWhy the need for patch releases then like 128.3.1?
- suprjami 2y ago128 is the current ESR: https://whattrainisitnow.com/calendar/ https://whattrainisitnow.com/calendar/
- hannob 2y agoWhat are you talking about? The fix was released today, and FF says they received the report 25 hours before that: https://infosec.exchange/@attackanddefense/113282079430280742 https://infosec.exchange/@attackanddefense/11328207943028074...
- okasaki 2y ago"Fixed in Firefox 131.0.2" which was released 21 hours ago? (https://ftp.mozilla.org/pub/firefox/releases/131.0.2/ https://ftp.mozilla.org/pub/firefox/releases/131.0.2/)
- jokoon 2y agoBecause if you make it public too early, it gives some time for attackers to write exploit to target unpatched versions. Firefox is used in other projects, so the patch needs to spread, and time is needed.
- olga11 2y ago[flagged]
- high_na_euv 2y agoWe need a browser written in managed lang Even if it means some perf drop, modern hardware will get it back in X years, but safety will be significantly improved
- SoothingSorbet 2y agoWhy managed when it could be in Rust and have both performance and safety? The Servo shouldn't have ever been laid off. Yes, I'm aware a team is working on it now, but it isn't up to the same speed and enthusiasm as it was when funded by Mozilla, is it?
- high_na_euv 2y agoIm aware of Rust, but there is C#/Java too, with way bigger ecosystem, community and lower entry level. At the end of the day web browser is just bunch of parsers and compilers working together, and some video/audio
- eqvinox 2y agoServo exists, in Rust. I don't know of any browser engine in C#/Java? Also, modern browsers as a whole outsize entire OSes (sans browser)...
- cesarb 2y ago> I don't know of any browser engine in C#/Java? A famous one is HotJava. According to Wikipedia, it was also the first web browser to support Java applets.
- Yoric 2y agoIt was also a mess :)
- eqvinox 2y ago> A famous one is HotJava. "Final release: Late 2004; 20 years ago" I guess I should've specified "not completely and utterly dead"? ;D (Also, the size and complexity of a browser at that point in time was arguably still a whole lot less than a modern one)
- olga11 2y ago[flagged]
- pixelesque 2y agoRedhat bugzilla has a tiny bit more info about dates (looks like very recent?) and is public: https://bugzilla.redhat.com/show_activity.cgi?id=2317442 https://bugzilla.redhat.com/show_activity.cgi?id=2317442 and likely affects Thunderbird as well by the looks of things.
- sylware 2y agountil the next one... It has been like that for most 'internet software' in the last decades, no light at the end of this tunnel.
- nullc 2y agoRegain your ability to sleep at night: https://www.qubes-os.org/ https://www.qubes-os.org/
- fransje26 2y agoFrom your experience, what are the system requirements needed to use that as comfortably as your daily driver?
- nullc 2y agoThey're increased, and some things are just obviously slow at least without extra effort to setup things like gpu pass-through. But is it worth basically turning back the clock on your computer's performance a few years to live in a world where a random click from HN or reddit can't quietly compromise your entire computer? I think so. Probably the biggest thing is to have a lot of ram, because if you're really using the virtualization it's a bit ram inefficient. Many things I expected to be hard or annoying just turn out to be non-issues. Qubes has lots of good automation to make it pretty seamless to use multiple VMs. I was already a fedora user, so I just copied my old home into a new app vm and was instantly productive. Then over time I weaned myself off the monolithic legacy vm into partitioned VMs.
- mikedelfino 2y ago> a world where a random click from HN or reddit can't quietly compromise your entire computer Doesn't Flatpak also solve this?
- nullc 2y agoNo, flatpack is very much not a security sandbox.
- mikedelfino 2y agoDo you mean you don't trust it? Because they do describe its sandboxing as a security feature.
- KwanEsq 2y agoThe patch: https://hg.mozilla.org/releases/mozilla-release/rev/d2a21d941ed5a73a37b3446caa4a49e74ffe854b https://hg.mozilla.org/releases/mozilla-release/rev/d2a21d94...
- palata 2y ago> The vulnerability impacts the latest Firefox (standard release) and the extended support releases (ESR). Does that mean it impacts Firefox 131.0.+, Firefox ESR 115.16.+ and Firefox ESR 128.3.+? I.e. Firefox 130.0.+ or Firefox ESR 114.+.+ are fine? It's not clear to me when the vulnerability was introduced...
- olejorgenb 2y ago> This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, and Firefox ESR < 115.16.1. https://nvd.nist.gov/vuln/detail/CVE-2024-9680 https://nvd.nist.gov/vuln/detail/CVE-2024-9680
- krackers 2y agoCVE affected range is always far too wide. It obviously can't affect anything before ~75 or so because firefox didn't have the timeline api before then. It's annoying that they don't distinguish an unknown lower bound.
- illiac786 2y agoWell, I think their thinking is that: * we don’t want users to run 75 * 75 is so riddled with CVEs by now, who cares if there is one more But I agree it’s appears lazy because it would have been easy to determine in that case, if I understood you correctly. Someone would have had to test it though, at the very least.
- acidburnNSA 2y agoGot my update on Ubuntu this morning, but not seeing any updates for Firefox Android in Google Play yet.
- NicolaiS 2y agoA note for Ubuntu users; if Firefox is installed using `snap` (default) and you run `snap refresh` it will output "All snaps up to date" - but this is not true! You have to close firefox, then run `snap refresh` for snap to upgrade firefox...
- guerrilla 2y agoNot an Ubunutu or snap user but curious, why?
- fhars 2y agoThe snap store also complains regularly that it can't updte the snap store because the snap store is running. It is just terrible software overall.
- lifthrasiir 2y agoNeither am I, but seems that snap refreshes can be inhibited programmatically if they may cause some damage when proceeded in the background. So it is technically correct that no snap refreshes can be performed at this point, but the message doesn't clearly state that some refreshes have been inhibited (possibly because there would be tons of them if they are exhaustively listed?).
- dspillett 2y agoIt doesn't update actively running application containers. You don't actually need to stop it before running “snap refresh” though, it'll just be out of date as long as it is kept open. Once the application stops running, next time it is run the updated image will be used. [caveat: I'm not a snap user myself currently, so my information may be inaccurate, take with a pinch of your favourite condiment]
- guerrilla 2y agoInteresting. On Arch, Firefox just refuses to keep working after I've updated and requests me to restart it.
- calyhre 2y agoIt's fixed in the developer edition 132.0b5 also if you are wondering
- Ennea 2y agoI was indeed wondering. Thank you.
- deleted 2y ago[deleted]
- jokoon 2y agoI wonder how many skilled black hats work for Iran, China or Russia. And I can imagine that those countries use front companies to buy exploit. I just hope that those blackhats understand that their discovery might land in the wrong hands. I guess those blackhats don't like authoritarian regimes.
- rightbyte 2y agoThis seems quite bad, but how practical is it. Like, the attacker will get write and read access to part or the whole of some other object allocated on the heap, when the memory is reused? Seems hard to do anything useful with.
- spirobelv2 2y agothis is the change that fixed it https://github.com/mozilla/gecko-dev/commit/7a85a111b5f42cdc07f438e36f9597c4c6dc1d48 https://github.com/mozilla/gecko-dev/commit/7a85a111b5f42cdc...