On CNET: Slow start for the Motorola Droid?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Dec 13, 2005 11:47:00 PM

If you haven't updated your Firefox or Mozilla Web browser lately, now might be a good time to do so.

Computer code that demonstrates how a known flaw in an older version of the browsers can be exploited in a potentially crippling attack was published on the Web over the weekend. The vulnerability was fixed in Firefox 1.0.5, released in July, and in Mozilla Suite 1.7.9, according to Mozilla.

The code was published by Aviv Raff, a developer in Israel. "I think it's been enough time for people to upgrade from v1.0.4 of Firefox," he wrote on his blog Sunday. Raff's code doesn't do much harm, but he notes that it would be easy to turn it into malicious code that commandeers a vulnerable system.

The vulnerability is in the way the Web browsers handle JavaScript, according to a Mozilla alert dated July 12, the day Firefox 1.0.5 was released. An attacker could craft a malicious Web site that, when accessed by a vulnerable PC, could let a attacker run code on that system without the owner realizing it.

Mozilla has released several updates to both Firefox and the Mozilla Suite since July. The latest version of Firefox is 1.5, released late last month. A security vulnerability that could cause the browser to appear to hang has already been pinpointed in that version, but Mozilla says it is a minor problem.

In other browser news, Microsoft on Tuesday released a patch that fixes four vulnerabilities in Internet Explorer. The software maker deems two of the flaws "critical." One is already being used to attack IE users, Microsoft said in a bulletin.

Secunia is warning of a security flaw in version 8.01 of the Opera Web browsers. Earlier versions may also be affected, the security monitoring company said in an alert Tuesday. The flaw lies in the way the browser handles mouse clicks in new windows and in how it displays a dialog box for downloads, according to Secunia's advisory.

The Opera flaw could be exploited to trick people into downloading malicious programs, Secunia said. The company advised people to upgrade to Opera 8.0.2, which has been available since late July. Several other releases have since followed.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 33 Talkback(s)
memory handling bug in FF 1.5?
I recently upgraded to FF 1.5 and have had lots of crashes due to memory handling problems. Never had this before. I know the FF blog talks about memory leakage. Any ideas?... (Read the rest)
Posted by: davagain Posted on: 12/15/05 You are currently: a Guest | | Terms of Use
No problems here  Tim Patterson | 12/13/05
Fixed in Firefox 1.0.5?? That was about a year ago.  wackoae | 12/13/05
Your point is irrelevant...  toadlife | 12/13/05
Good  Jeff Spicoli | 12/13/05
It would be irrelevant for IE users  wackoae | 12/13/05
If they are so smart...  toadlife | 12/13/05
Because they are arrogant and naive, like most Linux users.  itanal | 12/14/05
Actually  georgep_z | 12/14/05
True, Mozilla needs to get the auto-update working for sure.  DonnieBoy | 12/14/05
Actually  nECrO_z | 12/13/05
let them get hacked  Jeff Spicoli | 12/13/05
You are forgeting that ...  wackoae | 12/13/05
right  Real World | 12/14/05
MOST  nECrO_z | 12/14/05
Don't assume their level of knowledge.  Grayson Peddie | 12/14/05
Fixed in Firefox 1.0.5?? That was about a year ago.  wackoae | 12/13/05
More like six months ago  zmud | 12/14/05
Whats the point exactly?  JoeMama_z | 12/13/05
Interesting how the Mozilla team downplayed this vulnerabilty  toadlife | 12/13/05
Most Firefox users  SQLServer | 12/14/05
Leads me to a question  NonZealot | 12/14/05
Successful Exploits  bhartman36 | 12/14/05
You're wrong  toadlife | 12/14/05
Wrong (corrected post - hopefully)  toadlife | 12/14/05
(nt)looks like they finally decided to update the vulerability to critical  toadlife | 12/14/05
Microsoft says so  georgep_z | 12/14/05
It doesn't matter georgie  toadlife | 12/14/05
Everyone is on 1.0.7 if not 1.5 by now!!!  xunil skcor | 12/14/05
Actually, I'm still running 1.04  worknman | 12/14/05
Advances in 1.5  nucrash | 12/14/05
How to get old extentions to work with FF1.5 Here we go: 1) change  wexwimpy@... | 12/15/05
No probably, everybody updates as soon as a point  Boot_Agnostic | 12/14/05
memory handling bug in FF 1.5?  davagain | 12/15/05

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More