ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Firefox attack code published

Joris Evers CNET News.com

Published: 14 Dec 2005 09:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

If you haven't updated your Firefox or Mozilla Web browser lately, now might be a good time to do so.

Computer code that demonstrates how a known flaw in an older version of the browsers can be exploited in a potentially crippling attack was published on the Web over the weekend. The vulnerability was fixed in Firefox 1.0.5, released in July, and in Mozilla Suite 1.7.9, according to Mozilla.

The code was published by Aviv Raff, a developer in Israel. "I think it's been enough time for people to upgrade from v1.0.4 of Firefox," he wrote on his blog on Sunday. Raff's code doesn't do much harm, but he notes that it would be easy to turn it into malicious code that commandeers a vulnerable system.

The vulnerability is in the way the Web browsers handle JavaScript, according to a Mozilla alert dated 12 July, the day Firefox 1.0.5 was released. An attacker could craft a malicious Web site that, when accessed by a vulnerable PC, could enable them to run code on that system without the owner realising it.

Mozilla has released several updates to both Firefox and the Mozilla Suite since July. The latest version of Firefox is 1.5, released late last month. A security vulnerability that could cause the browser to appear to hang has already been pinpointed in that version, but Mozilla says it is a minor problem.

In other browser news, Microsoft on Tuesday released a patch that fixes four vulnerabilities in Internet Explorer. The software maker deems two of the flaws "critical". One is already being used to attack IE users, Microsoft said in a bulletin.

Secunia is warning of a security flaw in version 8.01 of the Opera Web browsers. Earlier versions may also be affected, the security monitoring company said in an alert on Tuesday. The flaw lies in the way the browser handles mouse clicks in new windows and in how it displays a dialog box for downloads, according to Secunia's advisory.

The Opera flaw could be exploited to trick people into downloading malicious programs, Secunia said. The company advised people to upgrade to Opera 8.0.2, which has been available since late July.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
105 out of 199 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

SAP BASIS CONSULTANT - Support/Upgrade - NorthWest

The role being offered will involve delivery of support to upgrade projects of systems from R/3 4.5b to ECC 6.0 including building test systems and ...

Pre-Sales Consultant, Leading Business Solutions provider, Asset Suite

The Role: Pre-Sales Consultant, Asset Suite. The Asset Suite Presales Consultant is a key role within the International Sales Team. My client ...

URGENT Project Manager required- NHS iPM PAS upgrade

You will be implementing the LE2.2 iPM PAS upgrade and so you should have experience of implementing the iPM PAS as part of the national Project ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment