[ news_security_news ] Firefox Fixes Flaws, Releases 2.0.0.5
David Utter Staff Writer
2007-07-18
Security News RSS Feed
An issue with the firefoxurl URI handler has been corrected by the Mozilla Foundation, which began pushing out a patched version of Firefox 2 to its users.
The dialog screen advising a new version of Firefox is available should be popping up on computer screens everywhere. Firefox users should proceed with this update as soon as possible.
Problems began when a security researcher, Thor Lanholm, blogged about a problem with URLs passed from Internet Explorer to the firefoxurl URI handler. Arbitrary code could have been executed by the handler as received from IE, which does not validate input going to firefoxurl.
Though there was some argument early whether the problem should be blamed on Microsoft or Mozilla, it proved to be an issue Firefox needed to address.
Security firm Secunia also noted Mozilla fixed several other vulnerabilities with the 2.0.0.5 update. Those other problems presented memory corruption, arbitrary code execution, and script injection as threats to Firefox users.
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More news_security_news Articles
Security News RSS Feed
|
|