Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Mozilla Firefox Browser Engine Memory Corruption

Subscribe

Check Point Reference: CPAI-2010-113
Date Published:
Severity:
Source: Secunia Advisory SA35331
Industry Reference(s): CVE-2009-3382
Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Mozilla Foundation Firefox Prior to 3.0.11
Vulnerability Description
A memory corruption vulnerability was reported in Mozilla Firefox, a popular Web browser developed by Mozilla Foundation. This flaw is due to the way Mozilla Firefox handles first-letter CSS style elements. A remote attacker can exploit this vulnerability by persuading a target user to open a malicious webpage. Successful attacks could allow for code execution.
Update/Patch Available
The vendor, Mozilla, has released an advisory to address this vulnerability
Vulnerability Details
The vulnerability is due to an implementation error when handling the CSS pseudo-element first-letter. A remote attacker could exploit this vulnerability by persuading a target user to open a specially crafted web page. Successful exploitation may allow the attacker to execute arbitrary code on the vulnerable system with the privileges of the target user.

Protection Overview
The protection will detect and block HTML documents that misuse the CSS pseudo-element :first-letter.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Web Intelligence > HTML, and select the Exploit Specific Protections protection group.
3. Click Exploit Specific Protections (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: Exploit Specific Protections
Description: Exploit Specific Protections