On CBSSports.com: Play FREE College Fantasy Football
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Nov 1, 2006 8:52:00 PM

A second security flaw that could cause the new Firefox 2 browser to crash has been publicly disclosed.

The vulnerability lies in the way the open-source browser handles JavaScript code. Viewing a rigged Web page will cause the browser to exit, a representative for Mozilla, the publisher of the software, said Wednesday. Contrary to claims on security mailing lists, the bug cannot be exploited to run arbitrary code on a PC running Firefox 2, the representative said.

This flaw in the JavaScript Range object is different from the denial-of-service vulnerability in Firefox 2 that was confirmed by Mozilla last week. That bug is related to a more serious security hole, which was fixed in earlier versions of Firefox, the organization has said.

The two "crashers" are the only publicly released vulnerabilities that have been confirmed by Mozilla in the week since Firefox 2 was launched. The issues are only minor, the organization has said.

By contrast, Microsoft's Internet Explorer 7 update suffers from a spoofing flaw, discovered a week after Microsoft released IE 7 on Oct. 18. The vulnerability could help crooks mask phishing scams, the type of attack Microsoft designed the browser to thwart.

According to Secunia, a security monitoring company, there are at least two other vulnerabilities in IE 7. Microsoft has disputed these issues, saying that one reported problem lies in Outlook Express, not IE 7, and the other is a part of the product design, not a flaw.

Release of the new Web browsers set off a race among bug hunters to come up with the first security hole in either program. So far, though, none of the reported flaws could be exploited to hijack a PC running the browser, the most serious type of vulnerability.

  • Talkback
  • Most Recent of 27 Talkback(s)
What's your excuse?
You don't seem to be adding anything more here than say Donnie_Boy adds in a Microsoft article's talkback.

So if I get this right. You're saying it OK for you to bash anything but Micrsoft but if someone bashes Micrsoft you have to insult them? Hypocrite, if the hat fits....... (Read the rest)
Posted by: voska Posted on: 11/03/06 You are currently: Logged In | Log out
Another nail HerbieHightower   | 11/01/06
A bug here, a bug there, isn't that No_Ax_to_Grind   | 11/01/06
If is was MS software TheHonestTruth   | 11/01/06
And Microsoft's zkiwi   | 11/01/06
I would agree with you if NonZealot   | 11/01/06
Well... zkiwi   | 11/01/06
Again, I would agree with you if... NonZealot   | 11/01/06
waste Arm A. Geddon   | 11/01/06
Then... Tony Agudo   | 11/01/06
Your username is hypocritical ... buran   | 11/01/06
Hey No_Axe, notice the different types of responses? NonZealot   | 11/01/06
re: responses Arm A. Geddon   | 11/01/06
p.s. Arm A. Geddon   | 11/01/06
Well of course, the first requirement of a MS basher No_Ax_to_Grind   | 11/02/06
Look at the poster's ID voska   | 11/03/06
Buwahahahaha No_Ax_to_Grind   | 11/02/06
What's your excuse? voska   | 11/03/06
No dude ... Henaway   | 11/02/06
Was This Flaw Part of 1.x Too? nikoli   | 11/01/06
I'm quite disappointed in these new releases... ju1ce   | 11/01/06
Not quite tripolitan   | 11/01/06
It doesn't matter... ju1ce   | 11/02/06
You have to... Qbt   | 11/01/06
Don't get me wrong... ju1ce   | 11/02/06
Firefox 2 looks like it is still in beta... Scrat   | 11/02/06
The term DOS has a specific meaning - article title misleading Steven Rogers   | 11/02/06
Spin, spin, spin TonyMcS   | 11/02/06

What do you think?

advertisement
Click Here