{"id":3472,"date":"2005-07-13T08:59:43","date_gmt":"2005-07-13T08:59:43","guid":{"rendered":"http:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/e-commerce\/playing-with-firefox.html"},"modified":"2005-07-13T08:59:43","modified_gmt":"2005-07-13T08:59:43","slug":"playing-with-firefox","status":"publish","type":"post","link":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/e-commerce\/playing-with-firefox.html","title":{"rendered":"Playing with FireFox"},"content":{"rendered":"<p class=\"MsoNormal\"><font size=\"2\"><span style=\"font-size: 10pt;\">I have been using FireFox more and more recently and was amused to find out<br \/>\nthat when I went to <a href=\"http:\/\/www.officeupdate.com\/\">Microsoft Office<br \/>\nUpdate<\/a> I was told I need to use IE to download the required patches. I am<br \/>\nno expert on monopolies but there seems to be something unfair about being<br \/>\nforced into having a copy of IE on hand to make sure you can upgrade your<br \/>\nsoftware.<\/p>\n<p>The same thing holds true for <a href=\"http:\/\/www.windowsupdate.com\/\">Windows<br \/>\nUpdate<\/a>. I would think the EU and the DOJ\/FTC would be up in arms about such<br \/>\npractices.<\/p>\n<p>Here is the e-mail regarding a security flaw in Office that started me down<br \/>\nthis path:<\/p>\n<p><span>&nbsp;<\/span>National Cyber Alert System<\/p>\n<p><span>&nbsp;<\/span>Technical Cyber<br \/>\nSecurity Alert TA05-193A<\/p>\n<p><span>&nbsp;<\/span>Microsoft Windows, Internet<br \/>\nExplorer, and Word Vulnerabilities<\/p>\n<p><span>&nbsp;<\/span>Original release date: July 12, 2005<br \/>\n<span>&nbsp;<\/span>Last revised: &#8212;<br \/>\n<span>&nbsp;<\/span>Source: US-CERT<\/p>\n<p>Systems Affected<\/p>\n<p><span>&nbsp;<\/span>* Microsoft Windows<br \/>\n<span>&nbsp;<\/span>* Microsoft Office<br \/>\n<span>&nbsp;<\/span>* Microsoft Internet Explorer<\/p>\n<p><span>&nbsp;<\/span>For more complete information, refer<br \/>\nto the Microsoft Security<br \/>\n<span>&nbsp;<\/span>Bulletin Summary for July, 2005.<\/p>\n<p>Overview<\/p>\n<p><span>&nbsp;<\/span>Microsoft has released updates that<br \/>\naddress critical vulnerabilities<br \/>\n<span>&nbsp;<\/span>in Windows, Office, and Internet<br \/>\nExplorer. Exploitation of these<br \/>\n<span>&nbsp;<\/span>vulnerabilities could allow a remote,<br \/>\nunauthenticated attacker to<br \/>\n<span>&nbsp;<\/span>execute arbitrary code on an affected<br \/>\nsystem.<\/p>\n<p><st1:place w:st=\"on\">I.<\/st1:place> Description<\/p>\n<p><span>&nbsp;<\/span>Microsoft Security Bulletins for July,<br \/>\n2005 address vulnerabilities in<br \/>\n<span>&nbsp;<\/span>Windows, Office, and Internet<br \/>\nExplorer. Further information is<br \/>\n<span>&nbsp;<\/span>available in the following<br \/>\nVulnerability Notes:<\/p>\n<p><span>&nbsp;<\/span>VU#218621 &#8211; Microsoft Word buffer<br \/>\noverflow in font processing routine<\/p>\n<p><span>&nbsp;<\/span>A buffer overflow in the font processing<br \/>\nroutine of Microsoft Word may<br \/>\n<span>&nbsp;<\/span>allow a remote attacker to execute<br \/>\ncode on a vulnerable system.<br \/>\n<span>&nbsp;<\/span>(CAN-2005-0564)<\/p>\n<p><span>&nbsp;<\/span>VU#720742 &#8211; Microsoft Color Management<br \/>\nModule buffer overflow during<br \/>\n<span>&nbsp;<\/span>profile tag validation<\/p>\n<p><span>&nbsp;<\/span>Microsoft Color Management Module<br \/>\nfails to properly validate input<br \/>\n<span>&nbsp;<\/span>data, allowing a remote attacker to<br \/>\nexecute arbitrary code.<br \/>\n<span>&nbsp;<\/span>(CAN-2005-1219)<\/p>\n<p><span>&nbsp;<\/span>VU#939605 &#8211; JVIEW Profiler<br \/>\n(javaprxy.dll) COM object contains an<br \/>\n<span>&nbsp;<\/span>unspecified vulnerability<\/p>\n<p><span>&nbsp;<\/span>The JVIEW Profiler COM object contains<br \/>\nan unspecified vulnerability,<br \/>\n<span>&nbsp;<\/span>which may allow a remote attacker to<br \/>\nexecute arbitrary code on a<br \/>\n<span>&nbsp;<\/span>vulnerable system.<br \/>\n<span>&nbsp;<\/span>(CAN-2005-2087)<\/p>\n<p>II. Impact<\/p>\n<p><span>&nbsp;<\/span>Exploitation of these vulnerabilities<br \/>\ncould allow a remote,<br \/>\n<span>&nbsp;<\/span>unauthenticated attacker to execute<br \/>\narbitrary code with the privileges<br \/>\n<span>&nbsp;<\/span>of the user. If the user is logged on<br \/>\nwith administrative privileges,<br \/>\n<span>&nbsp;<\/span>the attacker could take control of an<br \/>\naffected system.<\/p>\n<p>III. Solution<\/p>\n<p>Apply Updates<\/p>\n<p><span>&nbsp;<\/span>Microsoft has provided the updates for<br \/>\nthese vulnerabilities in the<br \/>\n<span>&nbsp;<\/span>Security Bulletins and on the<br \/>\nMicrosoft Update site.<\/p>\n<p>Workarounds<\/p>\n<p><span>&nbsp;<\/span>Please see the individual<br \/>\nVulnerability Notes for workarounds.<\/p>\n<p>Appendix A. References<\/p>\n<p><span>&nbsp;<\/span>* Microsoft Security Bulletin<br \/>\nSummary for July, 2005<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/www.microsoft.com\/technet\/security\/bulletin\/ms05-jul.mspx\">http:\/\/www.microsoft.com\/technet\/security\/bulletin\/ms05-jul.mspx<\/a>&gt;<\/p>\n<p><span>&nbsp;<\/span>* US-CERT Vulnerability Note<br \/>\nVU#218621<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/218621\">http:\/\/www.kb.cert.org\/vuls\/id\/218621<\/a>&gt;<\/p>\n<p><span>&nbsp;<\/span>* US-CERT Vulnerability Note<br \/>\nVU#720742<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/720742\">http:\/\/www.kb.cert.org\/vuls\/id\/720742<\/a>&gt;<\/p>\n<p><span>&nbsp;<\/span>* US-CERT Vulnerability Note<br \/>\nVU#939605<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/939605\">http:\/\/www.kb.cert.org\/vuls\/id\/939605<\/a>&gt;<\/p>\n<p><span>&nbsp;<\/span>* CAN-2005-0564<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CAN-2005-0564\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CAN-2005-0564<\/a>&gt;<\/p>\n<p><span>&nbsp;<\/span>* CAN-2005-1219<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CAN-2005-1219\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CAN-2005-1219<\/a>&gt;<br \/>\n<span>&nbsp;<\/span><br \/>\n<span>&nbsp;<\/span>* CAN-2005-2087<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CAN-2005-2087\">http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CAN-2005-2087<\/a>&gt;<br \/>\n<span>&nbsp;<\/span><br \/>\n<span>&nbsp;<\/span>* Microsoft Update<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/update.microsoft.com\/\">http:\/\/update.microsoft.com\/<\/a>&gt;<\/p>\n<p><span>&nbsp;<\/span>* Microsoft Update Overview<br \/>\n<span>&nbsp;<\/span>&lt;<a href=\"http:\/\/www.microsoft.com\/technet\/prodtechnol\/microsoftupdate\/defa\">http:\/\/www.microsoft.com\/technet\/prodtechnol\/microsoftupdate\/defa<\/a><br \/>\n<span>&nbsp;<\/span>ult.mspx&gt;<\/p>\n<p><span>&nbsp;<\/span>_________________________________________________________________<\/p>\n<p><span>&nbsp;<\/span>Feedback can be directed to the<br \/>\nUS-CERT Technical Staff.<\/p>\n<p><span>&nbsp;<\/span>Please send mail to cert@cert.org with<br \/>\nthe subject:<\/p>\n<p><span>&nbsp;<\/span>&quot;TA05-193A Feedback<br \/>\nVU#720742&quot;<br \/>\n<span>&nbsp;<\/span>_________________________________________________________________<\/p>\n<p><span>&nbsp;<\/span>This document is available at<\/p>\n<p><span>&nbsp;<\/span>&lt;<a href=\"http:\/\/www.us-cert.gov\/cas\/techalerts\/TA05-193A.html\">http:\/\/www.us-cert.gov\/cas\/techalerts\/TA05-193A.html<\/a>&gt;<br \/>\n<span>&nbsp;<\/span>_________________________________________________________________<\/p>\n<p><span>&nbsp;<\/span>Produced 2005 by US-CERT, a government<br \/>\norganization.<br \/>\n<span>&nbsp;<\/span>_________________________________________________________________<\/p>\n<p><span>&nbsp;<\/span>Terms of use<\/p>\n<p><span>&nbsp;<\/span>&lt;<a href=\"http:\/\/www.us-cert.gov\/legal.html\">http:\/\/www.us-cert.gov\/legal.html<\/a>&gt;<br \/>\n<span>&nbsp;<\/span>_________________________________________________________________<\/p>\n<p><span>&nbsp;<\/span>Revision History<\/p>\n<p><span>&nbsp;<\/span>July 12, 2005: Initial release<\/p>\n<p><span>&nbsp;<\/span>Last updated July 12, 2005<o:p \/><\/span><\/font><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have been using FireFox more and more recently and was amused to find out that when I went to Microsoft Office Update I was told I need to use IE to download the required patches. I am no expert on monopolies but there seems to be something unfair about being forced into having a<\/p>\n","protected":false},"author":44,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/3472"}],"collection":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/users\/44"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/comments?post=3472"}],"version-history":[{"count":0,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/posts\/3472\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/media?parent=3472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/categories?post=3472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.tmcnet.com\/blog\/rich-tehrani\/wp-json\/wp\/v2\/tags?post=3472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}