On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Sep 15, 2005 3:26:00 AM

The Mozilla Foundation plans to "shortly" release new versions of its Firefox and Mozilla Web browsers to address a recently disclosed serious security bug as well as several additional flaws, a representative said Wednesday.

The decision for new, so-called point releases was made after the disclosure last week of a problem in the way the browsers handle International Domain Names, or IDNs, Web addresses that use international characters. The vulnerability could let attackers secretly run malicious software on users' PCs. Hackers have been working on exploits for the flaw.

"As soon as we got the report that users might be impacted, we began evaluating our options," said Mike Schroepfer, director of engineering at the Mozilla Foundation. Firefox version 1.0.7 and Mozilla version 1.7.12, which fix the IDN flaw, are now being tested, he said. "We're releasing as soon as we possibly can."

The testing process is to make sure the updates don't introduce any compatibility problems, he said.

In addition to patching the IDN bug, the new releases include one functionality fix and a handful of fixes for yet undisclosed security problems, Schroepfer said.

The Mozilla Foundation, which distributes and coordinates the development of Firefox and Mozilla, responded swiftly to the IDN bug disclosure last week and within 24 hours provided a temporary fix. Though the fix disables support for IDNs, the new updates that are now being tested will actually fix the vulnerability and re-enable IDNs, Schroepfer said.

IDNs have caused trouble for Mozilla in the past. A Firefox security update in February fixed a flaw that would allow domain spoofing using the special domain names.

As the Mozilla Foundation and the open-source community were working on fixing the IDN flaw, the discoverer of that bug reported yet another issue with Firefox. Security researcher Tom Ferris on Wednesday said that Firefox1.5 beta 1 is vulnerable to a problem similar to the IDN bug he disclosed last week.

Another Firefox flaw?
Even with the fix that disables IDN installed, a buffer overflow vulnerability exists in Firefox 1.5 beta 1, Ferris wrote on his Security Protocols Web site. The problem is a variant of the original IDN bug, he wrote.

Buffer overflows are a commonly exploited security problem. They occur when a program allows data to be written beyond the allocated end of a buffer in memory. A computer can be made to execute potentially malicious code by feeding in extra data that is designed to flood over the buffer.

Firefox 1.5 beta 1 was released last week and is a test version of a new Firefox browser due out by year's end.

The Mozilla Foundation is investigating Ferris' latest report, Schroepfer said. "At this time, we're not sure whether it is a vulnerability," he said.

The latest problem occurs only in the beta release, which is meant for testing only and typically has bugs. The beta has been downloaded about 500,000 times, according to Schroepfer.

Firefox has risen in popularity in recent years as a viable alternative to Microsoft's Internet Explorer. Though its market share slipped slightly recently, researchers estimate that between 8 percent and 9 percent of the Internet population uses the open-source browser.

Security has been a main selling point for Firefox over Internet Explorer. However, Firefox has had its own security woes. Numerous serious holes in the browser have been plugged since its official release, and experts have said that safe Web browsers don't exist.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 112 Talkback(s)
FF Update...DON'T!!!!!
I used & loved Firefox. Then I downloaded the new Beta. Wham! It killed the browser...dead. Even restoring didn't help; the remaining browser remnants caused my McAffee to blow up and Windows XP wo... (Read the rest)
Posted by: FtWrth Posted on: 09/27/05 You are currently: a Guest | | Terms of Use
Interesting  Roger Ramjet | 09/15/05
it's not a patch  Real World | 09/15/05
Well, I hope the make both patches and the complete version available.  DonnieBoy | 09/15/05
They have yet to make  Real World | 09/15/05
You Betcha!  osreinstall | 09/15/05
why?  voska | 09/15/05
Actually, it bothers me more on Linux  Real World | 09/15/05
Annoyed with it on linux? Try it on BSD!  toadlife | 09/15/05
As do I, mi compadre  Real World | 09/15/05
well try to update IE in Linux  IceTheNet@... | 09/15/05
Big whoop  d.esposito@... | 09/22/05
Interesting  Loverock Davidson | 09/15/05
Who holds Microsoft accountable?  voska | 09/15/05
Yes they break things.  DemonX | 09/16/05
And it will  IT_User | 09/15/05
Accountable?  node357 | 09/15/05
Oh Please!!!  Cayble | 09/16/05
Good bye to the good ole days  IT Scion | 09/15/05
Let them find bugs in the 1.5 BETA.  Zogg | 09/15/05
The good ole days  node357 | 09/15/05
Good logic: so now that FF has larger installation base  michael_t | 09/16/05
Okay, Firefox fans  IT_User | 09/15/05
Maybe this will help  Otto_Delete | 09/15/05
Tabs  Loverock Davidson | 09/15/05
Did it, thanks  IT_User | 09/15/05
i might be mistaken  Monkey_MCSE | 09/15/05
I was gonna say the same thing  Jeff Spicoli | 09/15/05
Also..  Jeff Spicoli | 09/15/05
You can also use  Linux User 147560 | 09/15/05
yup  Jeff Spicoli | 09/15/05
Sorry but on Linux  Linux User 147560 | 09/15/05
dangit!  Jeff Spicoli | 09/15/05
On Linux  Hugh Jass | 09/15/05
You are  Qbt | 09/15/05
Oh come on...  jcs26 | 09/15/05
Slow down  Cayble | 09/16/05
Sure, no problem  CobraA1 | 09/15/05
Easy new tabs in FF  node357 | 09/15/05
Match the headline to the product:  John Zern | 09/15/05
CTRL-Click opens link in new Tab  David Hamilton | 09/17/05
Try these extensions  d.esposito@... | 09/22/05
FF Exploited Already  bka1959 | 09/15/05
Do you run any P2P Software?  ju1ce | 09/15/05
Re: Do you run any P2P Software?  bka1959 | 09/15/05
The possibility....  ju1ce | 09/15/05
Also, You May Have Visited A Website...  EBathory | 09/15/05
Then it would only be a cookie, not an actual installed application... (NT)  ju1ce | 09/15/05
Not a newB  bka1959 | 09/15/05
Spyware scaners  bka1959 | 09/15/05
Right...  ju1ce | 09/15/05
LOL, Have you ever used IE on any flavor of windows?  bka1959 | 09/15/05
Spyware Scanners  big-skip@... | 09/17/05
IE can bite you even if you don't open it  Otto_Delete | 09/15/05
Please explain how IE can infect your computer when you do not run it  balsover | 09/15/05
Easy...  ju1ce | 09/15/05
Re: Easy  bka1959 | 09/15/05
But I believe...  ju1ce | 09/15/05
What you have to realize  Qbt | 09/15/05
Who the hell said that?  ju1ce | 09/15/05
I agree  Cayble | 09/16/05
So what you're saying  lengua99 | 09/19/05
Not Really Bubba  osreinstall | 09/15/05
Purely from an Internet Standpoint you are correct...  ju1ce | 09/15/05
Yes But  bka1959 | 09/15/05
Nice try  IT Scion | 09/15/05
Ju1ce, you have been squeezed !  osreinstall | 09/15/05
You do know  lengua99 | 09/19/05
Outlook Express  bka1959 | 09/15/05
Is your java/javascript turned off in outlook also? (NT)  ju1ce | 09/15/05
Yes  bka1959 | 09/15/05
Common misconception  Real World | 09/15/05
Atleast one point of truth...  ju1ce | 09/15/05
Truth?  Real World | 09/15/05
Your method of saying...  ju1ce | 09/15/05
Important point  Cayble | 09/16/05
Current AV And Three Spyware Programs  bka1959 | 09/15/05
PS: Thanks for the advice though!  bka1959 | 09/15/05
Firewall  bka1959 | 09/15/05
Firewall & protection  big-skip@... | 09/17/05
Lol Re: Firewall & protection  bka1959 | 09/17/05
Very Interesting... RE: FF Exploited Already  LazLong | 09/15/05
creation/modification dates/times  bka1959 | 09/15/05
Had an interesting thought........  LazLong | 09/15/05
Re: Had an interesting thought  bka1959 | 09/15/05
Keyboard & other thoughts.....  LazLong | 09/15/05
OOPS......  LazLong | 09/15/05
Keyboard  bka1959 | 09/15/05
Spyware  georgep_z | 09/16/05
FF does not pretend to block spyware.  bka1959 | 09/16/05
Spyware  georgep_z | 09/16/05
Funny how an article about FF turns into a Microsoft add.  No_Ax_to_Grind | 09/15/05
Where did you learn to comprehend english?  EyeintheSky | 09/15/05
Nevermind comprehend, how about that spelling?...  Colonel_Panic | 09/15/05
Spelling  big-skip@... | 09/17/05
you have to stop and realize that most, if not all, of those posting here  bka1959 | 09/17/05
I'm Realy Disapointed  bka1959 | 09/15/05
Huh?  big-skip@... | 09/17/05
Time to take English/Spelling again!  bka1959 | 09/17/05
keybord  bka1959 | 09/17/05
I was responding to the previous poster. (NT)  ju1ce | 09/15/05
Good. Let's now the exprets compare  michael_t | 09/15/05
BTW: the expeRTs can talk too. ;;;-) nt  michael_t | 09/15/05
OK, Let's ...  PMC-CON | 09/16/05
ActiveX  ju1ce | 09/16/05
Really?  IT Scion | 09/16/05
I don't use Firefox for security...  supra5mge | 09/16/05
Why Firefox?  big-skip@... | 09/17/05
Wrong  nycran | 09/19/05
False Hopes  thematrix_z | 09/19/05
Firefox user  attower1@... | 09/22/05
I still use firefox no matter what  xkmail | 09/25/05
FF Update...DON'T!!!!!  FtWrth | 09/27/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More