Firefox security hole reported
Posted on 12 Sep 2005 at 10:31
Firefox users have been alerted to a potential security flaw in the open source browser. The news will come as an embarrassment to the developers who have just released a beta of version 1.5 which is intended to address a number of security issues.
According to security researcher Tom Ferris a buffer overflow vulnerability exists within the current Firefox version 1.0.6, all previous versions and the beta of 1.5. Ferris says a strikingly simple piece of HTML can allow an attacker to remotely execute arbitrary code on an affected host.
Ferris says he has notified the team at Mozilla about the problem and awaits their response. The Mozilla team says they are currently investigating the reported vulnerability. However, Ferris's claims cannot be easily dismissed as he has a track record of discovering new bugs in Windows software.
Although initially billed as a more secure browser than Internet Explorer, Firefox has had its own share of security problems in the past few months. However, the Mozilla team is pressing ahead with the new versions ahead of the next release of Internet Explorer expected before the end of the year.
A roadmap for the development of Firefox is available at the Mozilla web site.
Author: Steve Malone
advertisement
- Microsoft shows courage at Tech-Ed 09
- PowerPoint and Silverlight: a perfect match?
- Why all the fuss over Windows Explorer?
- Your iPhone has a virus? Well it's your fault
- Motorola pays Lucas for its Droid
- Where are the killer apps for Windows?
- Will you hit the Orange iPhone "unlimited" cap?
- USB 3 first benchmark - it's here, and it's fast
- Why Windows 7 has forced me to worry about security
- How Dixons is (under)selling Windows 7
- Avira Premium Security Suite 9
- ZoneAlarm Internet Security Suite
- Webroot Internet Security Essentials
- Trend Micro Internet Security
- PC Tools Internet Security 2009
- Panda Internet Security 2009
- Norton Internet Security 2009
- Kaspersky Internet Security 2009
- F-Secure Internet Security 2009
- Eset Smart Security
- BitDefender Total Security 2009
advertisement

Printed from www.pcpro.co.uk
