ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mozilla fixes 10 security flaws

Published: 16 Sep 2004 10:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The latest releases of the Mozilla and Firefox browsers, along with the Thunderbird email software, fix 10 security issues, including three critical vulnerabilities, according to the Mozilla Foundation, which develops the software.

The three critical flaws could let an attacker run code on the victim's computer, according to information published by the Mozilla Foundation on Tuesday. The vulnerabilities are caused by the improper handling of electronic business cards, known as vCards; overly large images in the bit map (BMP) format; and links that have host names using nonprintable characters.

The issues are fixed in the latest versions of the Mozilla Foundation's open-source software products: Mozilla 1.7.3, Firefox release candidate 1.0 and Thunderbird 0.8.

Security information provider Secunia gave the set of 10 holes a "highly critical" rating, its second-highest grade for Internet threats.

The plethora of new security issues comes a month after the Mozilla Foundation started offering money to researchers who found verifiable security problems in the browser. On Tuesday, the open-source group released its latest version of its software packages.

The Firefox browser in particular has benefited from the perception that its rival, Microsoft's Internet Explorer, suffers from security problems. A flaw revealed on Tuesday by Microsoft could put users of Internet Explorer at risk of having their PCs compromised by malicious Web sites.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
45 out of 86 people found this useful



Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Project Manager - Newcastle - EDS Excellent Salary + Flexible Benefits Package

The EDS Agile Enterprise Platform provides the road map needed to continually meet the client's needs. Foundation/Practitioner or PMP . Project ...

CISCO Technical Network EngineerCCNPWest Yorkshire-190pd - 3 months

My client is looking for a good all round candidate with a strong foundation in the routing and switching arena. This opportunity offers candidates ...

Graduate IT Developers

Instead, we celebrate individuality and well work with you to map out your very own training and career path. Youll also have the latest development ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation