ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Exploit published for old Firefox flaw

Joris Evers CNET News.com

Published: 07 Jul 2005 11:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer code that could be used to attack systems with older versions of Firefox has been released on the Internet, security experts have warned.

The exploit code takes advantage of a security vulnerability in Firefox 1.0.1 and earlier versions of the open source Web browser, the French Security Incident Response Team (FrSIRT) said in an advisory posted on Wednesday.

The bug exists because of an error in the way the older versions of Firefox handle GIF images. An attacker could gain control of a PC by luring the user to a Web page or sending an email containing a specially crafted image, according to FrSIRT, which rates the issue "critical."

Only Firefox 1.0.1 and earlier are vulnerable. The image-parsing problem was fixed in Firefox 1.0.2, which was released in March. Since then, two more Firefox updates have been released, mostly to address security issues. The most recent version is Firefox 1.0.4, which was released in May.

Because the security bug was quashed more than three months ago, the exploit release is less of a concern, said Michael Sutton, a lab director at security company iDefense. "Given the length of time during which patches have been available, I would consider the release of this exploit to be a credible threat, but not critical," he said.

A representative for the Mozilla Foundation, the maker of Firefox, said most of the browser's users have upgraded to version 1.0.4. Mozilla encourages people to check for updates regularly and update their browser when a new version is available, the representative said.

Since the debut of Firefox 1.0 in November, its usage has grown at a rapid pace. Security has been a main selling point for Firefox over Microsoft's rival Internet Explorer. The number of downloads of the software is close to passing the 70 million mark, according to the download counter Spread Firefox Web site. That total represents downloads of all versions, so it doesn't necessarily represent individual users.

Firefox has demonstrated that the mature Web browser market, dominated by Internet Explorer, can be shaken up. IE has begun to see its market share dip slightly — a first in a number of years. Firefox US usage share reached nearly 7 percent at the end of April, according to tracking company WebSideStory.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
119 out of 232 people found this useful


Full Talkback thread

0 comments


Related Jobs

Senior Technical Support Analyst 35-50k

Phenomenal opportunity to work in the Financial Arena A fast pace leading software house has just released a position. They are seeking an ...

Senior Software Engineer - Abingdon

A global organisation based in the Abingdon area are currenly looking for a Senior C#/.NET Developer to develop and enhance software systems for ...

Front End Developer XHTML, CSS, Javascript, W3C

The successful candidate will need to: -Use information/interaction design skills to develop and document site structures, navigation flows, wire ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment