ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise applications Toolkit

Mozilla downplays Firefox 2.0 bugs

Joris Evers CNET News.com

Published: 26 Oct 2006 11:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A day after shipping Firefox 2.0, Mozilla on Wednesday largely rebutted two claims of security flaws in the latest version of the web browser.

Bug hunters appear to be in a race to uncover new security flaws in both Firefox 2.0 and Internet Explorer 7, which Microsoft released last week. Word of what appears to be the first publicly disclosed IE 7 vulnerability came Wednesday.

At least two bug reports that indicated they affected the new Firefox release crossed over popular security mailing lists this week. But Mozilla on Wednesday largely rebutted those claims.

"I would call it just noise," said Window Snyder, Mozilla's security chief. The two issues don't present any real risk to Firefox users, she said.

One of the problems is related to a vulnerability that was patched in an earlier version of Firefox. A report on the Bugtraq mailing list suggested that the issue, labelled "critical" by Mozilla, resurfaced in Firefox 2.0.

The report is incorrect, Snyder said. "The vulnerabilities that were identified were actually fixed," she said.

However, there is a related problem that can cause Firefox to crash. "The exploitable issues are fixed. There is a crash, but it is a denial of service," Snyder said. "We're going to look at it and make sure there is really nothing there."

Another report on the Full Disclosure mailing list suggested that there is a flaw in Firefox 2.0 that could be exploited to aid in cyberscams. The report included some computer code, but not enough for Mozilla to determine whether there is a problem, Snyder said.

"We don't have enough information to identify it. If we get more information, then we will investigate," she said.

Mozilla shipped Firefox 2 on Tuesday, nearly a week after Microsoft released IE 7. Both browsers have an emphasis on security and include features such as phishing shields to protect against fraudulent, data-thieving websites.

"This is one of the highest quality Firefox releases to date," said Mike Schroepfer, vice president of engineering at Mozilla. "We fixed more issues than we ever have before. All empirical and anecdotal evidence so far shows that this is one of the most solid and stable Firefox releases."

Security researchers are welcome to hunt for bugs in Firefox, Snyder said. However, those bugs should be reported responsibly to Mozilla, instead of disclosed publicly, she said.

"We think it is great that the security community is working so hard to help us identify bugs," Snyder said. "Once they are identified, we're able to fix them and we fix them quickly and that means customers are less at risk."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
1323 out of 1643 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

SAP BCS Support Consultant

Where possible, opportunities for improvements, both procedural and system based should be identified and communicated. Key Responsibilities: - ...

The Head of Information Security and Privacy Incident Response

The Head of Information Security and Privacy Incident Response is a senior member of the Vulnerability Management team with primary responsibility ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Featured Talkback

The internet is going to have do a lot of maturing before it is ready for this kind of traffic. Security is always going to be a problem, connectivity is poor, and most business's are unwilling for their employees to have open access.

By: ator1940

Read full story:
Microsoft prepares to take Office online