ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

Mozilla patches Firefox flaw

Published: 24 Mar 2005 09:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Mozilla Foundation issued a patch for a major security flaw in its Firefox browser on Wednesday and advised people to update their software.

The problem is caused by a buffer overflow in legacy Netscape code still included in the browser for animating GIF images, Chris Hofmann, director of engineering for Mozilla, said. Similar memory problems have affected Mozilla's browsers and Microsoft's Internet Explorer in the past. A malicious attacker could exploit them by creating carefully crafted image files that, when viewed by a victim in a browser, execute a program and compromise the system.

The flaw was discovered by Internet Security Systems, a network protection company, and patched before the public learned of the issue, Hofmann said.

"We are staying ahead and being proactive in fixing the code," he said. "The deciding factor, in this case, was the potential for this: It's a little easier for hackers to turn it into an exploit that could be dangerous."

The Mozilla Foundation released version 1.02 of Firefox on Wednesday to fix the problem and asked that all users to download and apply the patch.

Recently published data has prompted questions about the security of Firefox. Security technology provider Symantec said in this week's Internet Threat Report that during the second half of last year, 21 vulnerabilities affected Mozilla browsers and 13 flaws affected Internet Explorer.

However, only seven of the flaws in Firefox were considered "highly severe", compared with nine in Internet Explorer.

Mozilla's Hofmann pointed to the data as a positive indication that the developers were doing a good job of securing the Firefox code.

"As the data shows, the flaws are of lesser severity," he said. "The kinds of things the Microsoft's browser is vulnerable to is much more worrisome."

On Tuesday, Mozilla president Mitchell Baker predicted that Firefox won't suffer nearly as many security flaws as Internet Explorer and that the increasing popularity of the open source browser won't change that.

"Microsoft has a proven track record with Internet Explorer," Microsoft said in statement. "We continue to make significant investments in Internet Explorer, including Windows XP Service Pack 2, which features a much stronger security infrastructure to help thwart malware attacks, block suspicious content and eliminate many common spoofing attempts. In addition, Internet Explorer 7 will be a major upgrade that will focus on security."

Mozilla is currently reviewing the roughly two million lines of code that make up the Firefox browser to find similar vulnerabilities to those patched on Wednesday. Last August, the organisation offered a bounty to anyone who finds significant flaws in the software. The developers are looking with particular intensity at the legacy code that remains in the browser.

"Most of the things that we are looking at and fixing are potential exploits that no one has figured out how to exploit yet," Hofmann said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
60 out of 118 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Messaging Engineer

Fault fixing and fault progression as per system design and build documentation. ITIL Foundation or higher This role sits within a secure site and ...

IT Project Manager - IT Development Projects Oxfordshire REF: 2068

Manager to work in a high profile and innovative environment where there is considerable opportunity for growth and career progression as a broad ...

Esupport Analyst - Contract - Tier 1 Inv Banking

Exposure to financial markets, understanding time urgency Strong customer service skills Tech Microsoft office suite Internet Browsers IE and Firefox ...

Vista Upgrade Blog

The game's up for Vista

I got an interesting invite last night to the media launch of a dedicated gaming centre housed in an HMV store in central London. Resplendent with around 80 Quad core PCs and Dual... More

1 comment

Windows Driver Updates

Because of my recent adventures with Windows Vista on my Lifebook, I've had to learn about and deal with the differences between Vista and XP in third-party device driver distribution... More

2 comments

Windows XP SP3 Installed

I have downloaded and installed Service Pack 3 for Windows XP Professional on my Fujitsu Lifebook S6510. Everything went smoothly, and it seems to work just fine. I don't see anything... More

Post a comment

Discussions

Moley Moley

welcome to www.007trader.com

Saturday 17 May 2008, 11:37 PM

3 posts
Tallin Tallin

welcome to www.007trader.com

Saturday 17 May 2008, 11:11 PM

3 posts
Moley Moley

Pride

Saturday 17 May 2008, 10:10 PM

6 comments

Featured Talkback

"We don't recommend specific technologies — we promote the use of technology per se." What sort of nonsense is this?? Every Becta endorsed IT supplier to schools is a Microsoft shop. Every single one.

By: 1000193068

Read full story:
Becta takes Microsoft to the OFT