ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

Firefox flaw made public

Dawn Kawamoto CNET News.com

Published: 06 Apr 2005 09:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw has been discovered in the popular open source browser Firefox that could expose sensitive information stored in memory, Secunia has warned.

Firefox versions 1.0.1 and 1.0.2 contain the vulnerability, the security information company said in an advisory on Monday. The flaw stems from an error in the JavaScript engine that can expose arbitrary amounts of heap memory after the end of a JavaScript string. As a result, an exploit may disclose sensitive information in the memory, Secunia said.

"Unlike other browser flaws, this one is not subject to phishing or access to the system. But it can expose sensitive information from other Web sites you visited and the information you entered there," said Thomas Kristensen, Secunia chief technology officer.

While the flaw is only rated as "moderately critical" by Secunia, the rapid adoption of the open source browser means that many users may be at risk. Prior to the release of version 1.0, downloads of earlier versions of the browser had reached 8 million within the first 18 months.

The Mozilla Foundation, which makes the Firefox browser, is working on a patch, and no cases have been reported, a representative for the group said.

Secunia has developed a test that allows people to see whether their system is affected by the vulnerability.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
56 out of 137 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Web Developer - JavaScript, AJAX - Front End

Web Developer (JavaScript, AJAX, Prototype, JavaScript)- Front End Role Location: London Salary: 35,000 dependent on experience Essential Skills: ...

Mobile User Experience Designer - XHTML, HTML, Javascript and CSS skills, as well as WAP - London, South East

Mobile User Experience Designer - XHTML, HTML, Javascript and CSS skills, as well as WAP - London, South East The area: User Experience We follow a ...

Junior Java Developer Java / J2EE, JSP / JSF, Servlets, Struts, Javascript, CSS, HTML, XHTML Greater London

Junior Java Developer Java / J2EE, JSP / JSF, Servlets, Struts, Javascript, CSS, HTML, XHTML Greater London Location : Watford, Herts, South East ...

Vista Upgrade Blog

Windows XP SP3 Installed

I have downloaded and installed Service Pack 3 for Windows XP Professional on my Fujitsu Lifebook S6510. Everything went smoothly, and it seems to work just fine. I don't see anything... More

Post a comment

Vista vs. XP: The Final Retreat

I suppose that most people are getting tired of reading about Vista vs. XP. I know that I am getting tired of writing about. I'm getting even more tired of fighting with it. So this... More

Post a comment

Vista Memory Leak?

I'm wondering if anyone else has seen anything that looks like a memory leak in Vista? I've been running Vista Business on my Lifebook S6510 for several weeks now, and overall I'm... More

Post a comment

Featured Talkback

"We don't recommend specific technologies — we promote the use of technology per se." What sort of nonsense is this?? Every Becta endorsed IT supplier to schools is a Microsoft shop. Every single one.

By: 1000193068

Read full story:
Becta takes Microsoft to the OFT