https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 I find it really gross that they do not allow others to access it. This behavior damages the forks.
The source code for the fix is public. Presumably the bug report includes working exploit code. I don't see how this is "damaging" for forks.
Mozilla patches Firefox zero-day abused in the wild
31–40 of 111 posts
Re: Mozilla patches Firefox zero-day abused in the wild
#32It's in moments like this where I really dislike running Ubuntu and having to wait for the new build to be released.
Re: Mozilla patches Firefox zero-day abused in the wild
#33Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf
Re: Mozilla patches Firefox zero-day abused in the wild
#34Re: Mozilla patches Firefox zero-day abused in the wild
#35Earlier quoted context omitted.
The source code for the fix is public. Presumably the bug report includes working exploit code. I don't see how this is "damaging" for forks.
It is important to also understand what causes the issue, how it was exploited, etc. Plus I am pretty sure that they had the bug report before the fix was released.
Re: Mozilla patches Firefox zero-day abused in the wild
#36Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf
You can't be sure the same bug was exploited.
Re: Mozilla patches Firefox zero-day abused in the wild
#37Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf
Your friend should probably be browsing as a non-admin in a continuously-reimaged VM, separate from an air-gapped machine, if you have those kinds of attackers after you. Spooky..
Re: Mozilla patches Firefox zero-day abused in the wild
#38It's in moments like this where I really dislike running Ubuntu and having to wait for the new build to be released.
Consider trying the debian package until it is updated in your system.
https://incoming.debian.org/debian-buildd/pool/main/f/firefo...
Re: Mozilla patches Firefox zero-day abused in the wild
#39Earlier quoted context omitted.
True they could have been clearer on the versions affected, but tbh you should keep with the latest supported anyway. Security bug reports are often restricted for some time after a new release to help prevent reverse engineering to find the bug.
Please do not assume people are not running current release just because they are lazy and have not upgraded. The user experience was degraded at FF57 for many individuals who need extensions that will not work with ff>56 or that developers have abandoned out of frustration with Mozilla. When all the extensions I find necessary are functional (or with suitable replacements) I will switch.
Also I'm curious, what extensions are missing? Most of my pre-quantum extensions, such as Tree Style Tabs, have been updated now.
Re: Mozilla patches Firefox zero-day abused in the wild
#40Earlier quoted context omitted.
Mozilla can still give access for the developers of forks without opening it to the public before they (and the forks!) have managed to rollout a full update.
Anyone can run a fork though, I right now might be running my personal fork. This is part of the point of free software. Plus, you assume that the select few developers that are given the exploit information are trustworthy. The exploit being public from the first day is better than if even a single developer is untrustworthy or compromised.