Advertisement
Promo

Security threats Toolkit

Google Mail JavaScript flaw patched

Joris Evers CNET News

Published: 03 Mar 2006 09:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has fixed a flaw in Google Mail after the problem was disclosed by a blogger, the company said on Thursday.

The flaw could allow JavaScript code to run when viewing a message in Gmail, potentially allowing malicious code to be used by an attacker to compromise a Gmail account, according to a blogger who calls himself Anthony.

The blogger, who claims to be a 14-year-old student, found the flaw when sending code from his Yahoo Web mail account to his Gmail account, he wrote on Wednesday. The blog is hosted by Google's Blogger service.

Google fixed the flaw "very shortly after the initial blog post went up," it said. "We learned of a minor security flaw in Gmail a little while ago and worked quickly to fix the problem, which has now been resolved," the search firm said.

Because the vulnerability was fixed quickly, it likely never was exploited in any attacks, according to Google. Still, Google would have preferred to have been alerted to the flaw privately, instead of via a public blog.

"We encourage all vulnerability reporters to follow responsible disclosure practices and notify vendors first before making the vulnerability public," the representative said.

Flaws in online services are found regularly. Last December, Google fixed a security hole in the mechanism it uses to generate error pages for forbidden redirects and pages that don't exist on the Google Web site. The flaw opened the door to phishing scams, account hijacks and other attacks.

Similar flaws have been discovered and fixed in other parts of Google's Web site, as well as in Microsoft's Xbox 360 Web site and Yahoo's Web-based email service.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
57 out of 121 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:











Video icon

Video

Sentry Posts Blog

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters