| ||Thread Tools|
|7th January 2005, 14:12||#1|
Join Date: May 2002
Mozilla and Firefox flaws exposed
Mozilla and Firefox users were warned of a number of potentially troublesome security vulnerabilities this week.
The most serious flaw involves a buffer overflow bug in the way Mozilla processes the NNTP (news) protocol. The bug creates a means for hackers inject hostile code into vulnerable systems, providing they trick users into executing maliciously constructed news server links. All versions of Mozilla prior to 1.7.5 are affected. Firefox users are advised to make sure they are running version 1.0 to minimise any risk. The flaw was discovered by Maurycy Prodeus of Polish firm iSEC Security Research.
Next up, Secunia has discovered a flaw that creates a means to spoof the source displayed in the Firefox's download dialog box. The vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. Other versions may also be affected, Secunia warns. It advises Firefox users download links from untrusted sources pending the availability of patches from the Mozilla project.
Finally, there's a less serious problem affecting Firefox and its email client Thunderbird. Security researchers have found that temporary files are stored by the popular packages in a format that makes it possible for snoops to read the content of downloads and attachments of other users on the same machine.
|Thread||Thread Starter||Forum||Replies||Last Post|
|Mozilla Firefox 3.6 RC1 released: Faster than Google Chrome||jmke||WebNews||0||12th January 2010 17:17|
|Mozilla unleashes Firefox 3.6 BETA||jmke||WebNews||0||2nd November 2009 11:45|
|Mozilla Firefox 3.0 Vulnerability||jmke||WebNews||0||19th June 2008 09:51|
|Microsoft IE7 Vs Mozilla Firefox 2.0||jmke||WebNews||0||26th October 2006 08:20|
|Mozilla Firefox 3.0 Alpha 1||jmke||WebNews||0||11th April 2006 20:41|
|Mozilla Talks About Its Plans For Firefox 2.0||jmke||WebNews||0||19th February 2006 18:46|
|Mozilla Firefox 2.0 alpha on Feb 10||jmke||WebNews||0||19th January 2006 21:35|
|New Firefox, Mozilla releases to fix bugs||Sidney||WebNews||0||15th September 2005 18:43|
|Mozilla FireFox 1.0.1 released!||jmke||WebNews||2||2nd March 2005 12:25|
|Mozilla Firefox 1.0 Preview||jmke||WebNews||0||13th September 2004 12:32|