ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Google Mail JavaScript flaw patched

Joris Evers CNET News.com

Published: 03 Mar 2006 09:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Google has fixed a flaw in Google Mail after the problem was disclosed by a blogger, the company said on Thursday.

The flaw could allow JavaScript code to run when viewing a message in Gmail, potentially allowing malicious code to be used by an attacker to compromise a Gmail account, according to a blogger who calls himself Anthony.

The blogger, who claims to be a 14-year-old student, found the flaw when sending code from his Yahoo Web mail account to his Gmail account, he wrote on Wednesday. The blog is hosted by Google's Blogger service.

Google fixed the flaw "very shortly after the initial blog post went up," it said. "We learned of a minor security flaw in Gmail a little while ago and worked quickly to fix the problem, which has now been resolved," the search firm said.

Because the vulnerability was fixed quickly, it likely never was exploited in any attacks, according to Google. Still, Google would have preferred to have been alerted to the flaw privately, instead of via a public blog.

"We encourage all vulnerability reporters to follow responsible disclosure practices and notify vendors first before making the vulnerability public," the representative said.

Flaws in online services are found regularly. Last December, Google fixed a security hole in the mechanism it uses to generate error pages for forbidden redirects and pages that don't exist on the Google Web site. The flaw opened the door to phishing scams, account hijacks and other attacks.

Similar flaws have been discovered and fixed in other parts of Google's Web site, as well as in Microsoft's Xbox 360 Web site and Yahoo's Web-based email service.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
53 out of 117 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Security Consultant - Immediate start

The desired candidate will have the following skillset: * Network Vulnerability Internal & External Testing * Configuration of Cisco switches / ...

Inside Sales Representative

Activities - To achieve or exceed all elements of your quarterly sales targets by selling all-lines of business - Provide an excellent customer ...

Information Security Engineer - C++ or Java - London and EMEA

You will be performing security audits, risk analysis, application-level vulnerability testing and security code-reviews on a wide variety of ...

Sentry Posts Blog

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Google sponsors open source security p...

Google has announced it is to sponsor oCERT, an open source computer emergency response team. In a blog post on Monday, Google security engineer Will Drewry said that one of the... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation