iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Mozilla Sees Little Risk In Firefox 3 Flaw
Search:
[ insider_reports_insider ]

Mozilla Sees Little Risk In Firefox 3 Flaw



David Utter
Staff Writer
2008-06-20

SecurityProNews: Insider Reports Insider Reports RSS Feed


A vulnerability affecting both the latest version of the Firefox browser as well as the previous one, Firefox 2, poses minimal concerns for users according to Mozilla.

Mozilla Sees Little Risk In Firefox 3 Flaw
Mozilla Sees Little Risk In Firefox 3 Flaw

Mozilla security director Window Snyder confirmed the flaw, which poses a remote code execution threat. On the Mozilla Security blog, Snyder said they are investigating the issue.

"To protect our users, the details of the issue will remain closed until a patch is made available," Snyder said. "There is no public exploit, the details are private, and so the current risk to users is minimal."

A report from TippingPoint cited a flaw that had been privately reported to them through the Zero Day Initiative program. TippingPoint acquired the vulnerability from the researcher, and provided its details to Mozilla.

The security flaw requires user interaction, such as clicking on a malicious link. If people avoid risky behavior like this, the problem poses little threat.

Plenty of people picked up Firefox 3 upon its debut on June 17. Mozilla hyped the arrival as Firefox Download Day, where they sought and apparently achieved a world record number of downloads in a 24-hour period.

The event proved attractive to at least one vulnerability writer, with the flaw that was created gaining public awareness a few hours after the downloading started. As TippingPoint credited Mozilla's record of quickly responding to security concerns, we also believe Snyder and company will have a patch available soon for this problem.



About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds