Firefox security hole reported
By Steve Malone
Posted on 12 Sep 2005 at 10:31
Firefox users have been alerted to a potential security flaw in the open source browser. The news will come as an embarrassment to the developers who have just released a beta of version 1.5 which is intended to address a number of security issues.
According to security researcher Tom Ferris a buffer overflow vulnerability exists within the current Firefox version 1.0.6, all previous versions and the beta of 1.5. Ferris says a strikingly simple piece of HTML can allow an attacker to remotely execute arbitrary code on an affected host.
Ferris says he has notified the team at Mozilla about the problem and awaits their response. The Mozilla team says they are currently investigating the reported vulnerability. However, Ferris's claims cannot be easily dismissed as he has a track record of discovering new bugs in Windows software.
Although initially billed as a more secure browser than Internet Explorer, Firefox has had its own share of security problems in the past few months. However, the Mozilla team is pressing ahead with the new versions ahead of the next release of Internet Explorer expected before the end of the year.
A roadmap for the development of Firefox is available at the Mozilla web site.
From around the web
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
- Can you send a truly anonymous email?
- Is it safe to send bank details over email?
- Sainsbury's Bank bans password storage
- MobileMe triggers credit card blocks
- How to stay safe against session hijacking
advertisement
