On GameFAQs: The Top 10 Literature-Based Games
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Jul 13, 2005 12:55:00 AM

update The Mozilla Foundation has fixed several security flaws in its Firefox browser, but initially left people in the dark about what some of the issues entail.

Firefox 1.0.5, released Tuesday, patches a dozen bugs in the open-source Web browser, some of them "high risk," said Chris Hofmann, director of engineering at Mozilla. High-risk problems typically allow an intruder to commandeer a PC or expose the user's data.

"We have a collection of bug fixes that we have been working on for the last couple of weeks," Hofmann said Tuesday.

Two of the flaws that have been patched were reported in June by security-monitoring company Secunia, a Mozilla representative said.

Mozilla initially did not release details on the other vulnerabilities, even though the software revamp was available online around noon Tuesday.

Details on the bugs were published Tuesday night. Two of the 12 bugs are rated "critical" and another four are "high risk," according to Mozilla's security alerts. The bugs could allow an attacker to take over a victim's PC or expose sensitive user data, according to the alerts.

The update also includes improvements to make Firefox more stable, Mozilla said in its online posting.

Some of the security holes in Firefox were reported by Mozilla community members, helped by the group's bug bounty program, which provides $500 and a Mozilla T-shirt for finders of critical flaws, Hofmann said.

Most of the flaws would require some user interaction for an attacker to be able to exploit them, Hofmann said. There are no known attacks that use any of the newly fixed problems, he said.

The vulnerabilities reported by Secunia are spoofing flaws, which could let an attacker place malicious content on trusted Web sites. One problem lies in the way the browser handles frames. The other exists because JavaScript dialog boxes do not display or include their origin.

Firefox 1.0.5 is the first update to the popular alternative browser since May 11, when Mozilla released version 1.0.4 to fix three bugs.

Later this week, Mozilla plans to release a new version of its Thunderbird e-mail client. Thunderbird shares some code with Firefox and thus is vulnerable to the same security bugs, Hofmann said. An update to the Mozilla Suite is also scheduled to appear soon.

An alert mechanism in Firefox is designed to let people know that an update is available. They will have to download the full new browser, which is about 4.8MB in size. The next version of Firefox, release 1.1 due in August or September, will have a more streamlined patching mechanism that will let people download just the fixes, Hofmann said.

Since the debut of Firefox 1.0 in November, its usage has grown at a rapid pace. Security has been a main selling point for Firefox over rival Microsoft's Internet Explorer, which has begun to see its market share dip slightly--for the first time in a number of years. Firefox U.S. usage share reached nearly 7 percent at the end of April, according to tracking company WebSideStory.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 129 Talkback(s)
You see the man from outside the box
Good for you and those that see him for what he is! (Read the rest)
Posted by: JINKS Posted on: 07/23/05 You are currently: a Guest | | Terms of Use
Firefox update squashes security bugs  Loverock Davidson | 07/12/05
Must be magic!  cdgoldin | 07/13/05
Nice title  cforuself | 07/13/05
Titles & Headlines  Too Old For IT | 07/13/05
And the TV news  snowbeard | 07/13/05
Nice to notice some one else notices these things  John Zern | 07/13/05
Nice Title?  ryxr30 | 07/13/05
Really?  aforencich | 07/13/05
Firefox Update  tbige1939 | 07/13/05
I remember reading someplace  Jack-Booted EULA | 07/13/05
potential overload  Too Old For IT | 07/13/05
Update  bka1959 | 07/13/05
Firefox is NOT secure...  Mike Cox | 07/13/05
9.1- the irony hits the spot  el1jones | 07/13/05
Was it breakfast in bed?  tic swayback | 07/13/05
Doug Barney was invited by my rep...  Mike Cox | 07/13/05
Two in the same story  shallow_diver | 07/13/05
VB  SoToasty | 07/13/05
Worse than just VB  LinuxHippie | 07/13/05
Message has been deleted.  itanalyst | 07/13/05
Best ever  Sir_Chancealot | 07/13/05
9.9 for "thousands of servers and a 2:1 server to employee ratio"  tbbrickster_z | 07/13/05
You are something else  braynes_z | 07/14/05
ROFLMAOTIPMTU...  dalecosp | 07/13/05
celebrated over......  RTedrow | 07/13/05
The best security measure is to unplugg all.  nantic | 07/13/05
Pardon me?  raleo@... | 07/13/05
Hey ZDNet NOOB, Cox is a Known Satirist (nt)  tbbrickster_z | 07/13/05
The sad truth is that although Mike is joking  michael_t | 07/14/05
And here is our first example:  michael_t | 07/14/05
And our 2nd guest is  michael_t | 07/14/05
Oh let me....  monolith | 07/13/05
Not secure hugh?  jskline0@... | 07/13/05
Oh No...  UncleBubba | 07/13/05
Yeah!  hal9000mx | 07/13/05
Brilliant AND Original! I give it a 9.9!  Sir_Chancealot | 07/13/05
Nice story but where's your argument  midnightq | 07/13/05
Fresh Batch of NOOBs?!?!?  tbbrickster_z | 07/13/05
Satire?? What's that  HereInOz | 07/13/05
very biased  ashishwave@... | 07/13/05
Too good to be true!  MichaelAM | 07/13/05
Satire is alive and well in US culture  BigSens0r | 07/14/05
Anti-Apache ISA Plugin -- Replaces AV, AS, Stops IP Theft  PMC-CON | 07/14/05
LOLOLOLOL!!!  kokuryu | 07/14/05
Firefox = flawed.  Grayson Peddie | 07/13/05
...  boxmonkey | 07/13/05
New = Flawed  billisaacson | 07/13/05
Grayson T. Peddie = flawed  talisman | 07/13/05
Dirigibles O. Flotations  HereInOz | 07/13/05
Firefox is NOT secure...  grincity2003 | 07/13/05
All their clothes?  Real World | 07/13/05
Re All their clothes?  grincity2003 | 07/13/05
We're going to start requiring Open Source Undies...  dalecosp | 07/13/05
FireFox Is The Way To Go!  itanalyst | 07/13/05
BWahahaha!! The mountains of Nepal!!  Jeff Spicoli | 07/13/05
Awl b blizunt  ibabadur1 | 07/13/05
thank you, o illiterate one  Jeff Spicoli | 07/13/05
u r welcome, o intuitive one  ibabadur1 | 07/13/05
Beat It Ghetto Trash  itanalyst | 07/13/05
so sad  MichaelAM | 07/13/05
At least problems are getting fixed...  Colonel_Panic | 07/13/05
Do you make this shite up?  Jeff the god of biscuits | 07/13/05
Huh? I did not say M$ never patches IE...  Colonel_Panic | 07/13/05
That is not what you said  Jeff the god of biscuits | 07/13/05
I'm not "getting you wrong", but you got yourself wrong, methinks...  dalecosp | 07/13/05
Your right  Jeff the god of biscuits | 07/13/05
Perspective Please...  smegz | 07/13/05
That is my point  Jeff the god of biscuits | 07/13/05
Don't believe me? Take a look for yourself:  talisman | 07/13/05
Give me a break  Jeff the god of biscuits | 07/13/05
Your lucky break: http://www.cert.org  michael_t | 07/14/05
The site you mentioned is 'strange'  michael_t | 07/14/05
known knowns vs unknown unknowns  dan728 | 07/13/05
Hey buddy, RUN!  Real World | 07/13/05
Step aside, mjb, an' let me at 'im!  Judas I. | 07/13/05
All good, OB  Real World | 07/13/05
You're TOO good to 'im, mjb  Judas I. | 07/13/05
Can't Use Logic on a Con OB, only Liberals Use Rational Thinking  tbbrickster_z | 07/13/05
Uh oh, now yer in for it, tbbrickster.  Judas I. | 07/13/05
LOL!!! KY Jelly "liberally"?  tbbrickster_z | 07/14/05
10 Commandments  jdunigan@... | 07/13/05
Message has been deleted.  bybelknap | 07/14/05
Try "Poor put upon *American* xtians"  tbbrickster_z | 07/14/05
yo Obutterbrain  John Zern | 07/13/05
I can GUARANTEE you, John, that EVERYBODY here on Talkback,  Judas I. | 07/13/05
Get rid of all religion  JINKS | 07/18/05
Bush Hater  jdunigan@... | 07/13/05
IF Bush Told A Lie  mrchuckhall | 07/13/05
You see the man from outside the box  JINKS | 07/23/05
Clinton actually broke the law?  Judas I. | 07/13/05
Bush what a poor excuess for a human begin  JINKS | 07/18/05
Re: Unknown unknowns....  dan728 | 07/13/05
are you sure your not a republican?  jdunigan@... | 07/13/05
Republican is antithetic to "personally responsible."  Judas I. | 07/13/05
DAN728 you have accomplished  michael_t | 07/14/05
re: knowns vs unknowns  brent1a | 07/13/05
Bill Gates for President of Earth  jdunigan@... | 07/13/05
He is already the President (in his mind at least) nt  michael_t | 07/14/05
Where's the logic  High Sierra | 07/13/05
Oh, I agree except...  Allstar_z | 07/13/05
And to Think the Cons Gave Clinton Crap About What the Def. of Is Is. (nt)  tbbrickster_z | 07/13/05
Donald Rumsfeld (World renowned Security Expert)  talisman | 07/13/05
It makes so much sense! Kudos...  michael_t | 07/14/05
2:1 server to employee?  heml0ck | 07/13/05
I'm sure he meant it ... and here's some more news:  dalecosp | 07/13/05
ROTFLOL!!! 9.9 on the Links  tbbrickster_z | 07/13/05
Gunna go fire up Synaptic...  Colonel_Panic | 07/13/05
Anybody else notice that Image rendering VERY SLOW in 1.05  kchahal | 07/13/05
Must be your PC...  Nekow42 | 07/13/05
Don't think so  kchahal | 07/13/05
Extensions, maybe?  Nekow42 | 07/14/05
Mathematical Impossibility  jdunigan@... | 07/13/05
impossibility  falk-larsen | 07/13/05
Mine is much faster  kokuryu | 07/14/05
No, Rockin-and-a-Rolling Just Fine (nt)  tbbrickster_z | 07/14/05
OFF TOPIC Why can't ZDNet use...  AKN3t4dmin | 07/13/05
Yes! Yes! Yes!  Real World | 07/13/05
I Posted This Problem  PMC-CON | 07/14/05
A worrying trend regarding Firefox's security  Scrat | 07/14/05
ZDNet Must Be Making This Up ...  PMC-CON | 07/14/05
Firefox the ONLY way to go!  kokuryu | 07/14/05
Firefox 1.05 problem  usbpscm | 07/14/05
One of my clients was using a proxy server.  Judas I. | 07/14/05
Also...  Judas I. | 07/14/05
Connection problem  charliechan | 07/14/05
No, Connecting Just Fine (nt)  tbbrickster_z | 07/14/05
Firefox 1.05  walt747 | 07/15/05
Roboform for Firefox 1.0.5 is out...  Nekow42 | 07/16/05
Firefox 1.0.6 is out  andrejfavia@... | 07/20/05

What do you think?

advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More