ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mozilla patches Firefox URI flaw

Tom Espiner ZDNet.co.uk

Published: 26 Jul 2007 14:17 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw has been patched in Mozilla Firefox that could have allowed users' computers to be compromised by visiting websites infected with malware.

The flaw lay in the way Firefox version 2.0.0.5 handled uniform resource identifiers (URIs), protocols that allow browsers to access software. Firefox failed to properly handle some URIs, a flaw in the web browser that could have allowed remote malware execution.

Bugzilla@Mozilla posted the bug as "resolved fixed" on Wednesday. A link to the patch is available through the bug post.

Netscape Navigator 9 was also affected by the flaw, said Billy Rios, the security researcher who discovered the flaw.

Rios called for developers to pay more attention to possible URI-handling vulnerabilities in their code, after a spate of browser difficulties involving URIs in Internet Explorer and Firefox.

According to Rios, developers must be aware that applications installing URI handlers on a PC can give an extra attack vector, because an attacker can then embed a link to the application in a web page.

"Developers who intend to or have already registered URIs for their applications must understand that registering a URI handler exponentially increases the attack surface for that application," said Rios in his blog. "Please review your registered URI-handling mechanisms and audit the functionality called by those URIs."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
6 out of 8 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Malware Security Engineer

A leading publishing house is searching for a Malware Security Test Engineer to assist with the ever increasing workload and expanding business. ...

Embedded High-Speed Real-Time Control Systems Designer Hemel Hempstead

The ideal candidate will also be skilled in requirements capture and system specification, bug tracking database software and bug lifecycles, control ...

Technical Support Analyst / 1st and 2nd line Support Engineer Windows, Networks - REF: 2090

Performing a range of ICT management tasks, such as replacing classroom PCs, repairing failed components and resolving any network or equipment ...

Sentry Posts Blog

Working@Home: Keeping Secure

National Work from Home Day has come and gone, with an estimated five million people skiving to enjoy the comforts of their home. However, even though employees sat comfortably, IT... More

Post a comment

Privacy International director launche...

Simon Davies, who has been involved with campaigning on privacy issues for a number of years, is launching a privacy consultancy firm called 80/20. Half of all profits will be donated... More

Post a comment

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation