On mySimon: The Art of Shaving Engraved Shaving Set
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Oct 26, 2006 1:25:00 AM

A day after shipping Firefox 2, Mozilla on Wednesday largely rebutted two claims of security flaws in the latest version of the Web browser.

Bug hunters appear to be in a race to uncover new security flaws in both Firefox 2 and Internet Explorer 7, which Microsoft released last week. Word of what appears to be the first publicly disclosed IE 7 vulnerability came Wednesday.

At least two bug reports that indicated they affected the new Firefox release crossed over popular security mailing lists this week. But Mozilla on Wednesday downplayed those claims.

"I would call it just noise," said Window Snyder, Mozilla's security chief. The two issues don't present any real risk to Firefox users, she said.

One of the problems is related to a vulnerability that was patched in an earlier version of Firefox. A report on the Bugtraq mailing list suggested that the issue, labeled "critical" by Mozilla, resurfaced in Firefox 2.

The report is incorrect, Snyder said. "The vulnerabilities that were identified were actually fixed."

However, there is a related problem that can cause Firefox to crash. "The exploitable issues are fixed. There is a crash, but it is a denial of service," Snyder said. "We're going to look at it and make sure there is really nothing there."

Another report on the Full Disclosure mailing list suggested that there is a flaw in Firefox 2 that could be exploited to aid in cyberscams. The report included some computer code, but not enough for Mozilla to determine whether there is a problem, Snyder said.

"We don't have enough information to identify it. If we get more information, then we will investigate," she said.

Mozilla shipped Firefox 2 on Tuesday, nearly a week after Microsoft released IE 7. Both browsers have an emphasis on security and include features such as phishing shields to protect against fraudulent, data-thieving Web sites.

"This is one of the highest-quality Firefox releases to date," said Mike Schroepfer, vice president of engineering at Mozilla. "We fixed more issues than we ever have before. All empirical and anecdotal evidence so far shows that this is one of the most solid and stable Firefox releases."

Security researchers are welcome to hunt for bugs in Firefox, Snyder said, adding that those bugs should be reported responsibly to Mozilla, instead of disclosed publicly.

"We think it is great that the security community is working so hard to help us identify bugs," Snyder said. "Once they are identified, we're able to fix them and we fix them quickly and that means customers are less at risk."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 41 Talkback(s)
StanW
Since loading Firefox2 I get frequent alerts, "the connection to the server was reset while the page was being loaded." This doesn't happen with Explorer7. I also use PC-cillin but they say it isn't their problem.... (Read the rest)
Posted by: Unknown Posted on: 12/01/06 You are currently: a Guest | | Terms of Use
Well...  Qbt | 10/25/06
I agree....  andrej770 | 10/26/06
Oh! Isn't it wonderful  gsuser | 10/26/06
Experience counts  critic-at-arms | 10/26/06
Are they really the same?  MMs13s | 10/26/06
Yes and no  Qbt | 10/26/06
Great - I think...  MMs13s | 10/26/06
To expand  Qbt | 10/26/06
An exploit in FF can cause just as much damage as one in IE  PB_z | 10/26/06
To ensure clarity  Linux User 147560 | 10/26/06
To ensure clarity  Linux User 147560 | 10/26/06
Users are restricted from modified the core system files in Windows, too  PB_z | 10/27/06
Uh...  zoroaster | 10/26/06
I was about to say something like...  3D0G | 10/26/06
I agree  April May | 10/26/06
Well  Linux User 147560 | 10/26/06
pssstt.....  Shelendrea | 10/26/06
Got a ??? for you...  Linux User 147560 | 10/26/06
Not lately  Shelendrea | 10/26/06
Yeah...  Linux User 147560 | 10/26/06
Well duh  Shelendrea | 10/26/06
I don't know what disturbs me more  Shelendrea | 10/26/06
Not one bug but two ....  ShadeTree | 10/26/06
I saw that  Shelendrea | 10/26/06
You are entitled to that opinion.  ShadeTree | 10/26/06
FF2 Vs IECrud7  jackofalltradesmasterofnone | 10/26/06
Wrong, Linux.  tealcat | 10/30/06
Logic?  blackgaff | 10/27/06
FF 2 Rocks  Chad_z | 10/26/06
Chad_zzzzzzzzzzzzz  jguyp725@... | 10/26/06
I don't really like how Window Snyder sounds  duswil | 10/26/06
yup...  zoroaster | 10/26/06
Bravo  kd5djn | 10/26/06
Firefox?All Editions  Kris Kleeberg | 10/26/06
"There is a crash, but it is a denial of service"  PB_z | 10/26/06
Firefox 2  mikemerch@... | 10/26/06
Firefox problems?  John_Carter | 10/30/06
I found one bug...easily fixed  snow_wolf36@... | 10/30/06
Firefox 2  lewcock@... | 10/31/06
Re:Firefox 2  filrod@... | 10/31/06
StanW  null | 12/01/06

What do you think?

advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here