Mozilla admits Firefox is flawed just like IE
What's a 'critical vulnerability' for the goose is apparently the same for the gander
Computerworld - In a public mea culpa, Mozilla Corp.'s chief security officer acknowledged today that Firefox includes the same flaw that the company called a "critical vulnerability" in Internet Explorer during a two-week ruckus over responsibility for a Windows zero-day bug.
"Over the weekend, we learned about a new scenario that identifies ways that Firefox could also be used as the entry point," said Window Snyder of Mozilla. "While browsing with Firefox, a specially crafted URL could potentially be used to send bad data to another application.
"We thought this was just a problem with IE," Snyder continued. "It turns out, it is a problem with Firefox as well."
The argument over responsibility for a flaw that involved both IE and Firefox began two weeks ago, when Danish researcher Thor Larholm argued that IE contained an input validation bug that passes potentially malicious URLs to other applications. Larholm called out Firefox's "firefoxurl://" protocol as one that IE mishandled. He staked out the position that IE was to blame, while other security experts said it was Firefox's fault.
As fingers pointed, Mozilla patched the IE-Firefox interaction bug by releasing an update, Version 2.0.0.5. Even so, Snyder and others continued to argue that IE was the problem. "Microsoft needs to patch Internet Explorer," Snyder said last Wednesday. That same day, Asa Dotzler, director of community development, contrasted what he said were the differences between Microsoft and Mozilla on the bug. "We think it's Firefox's job to ensure that users are protected from malicious Web sites when they're surfing the Web in Firefox. Apparently, Microsoft doesn't think the same for IE," Dotzler said then.
Friday, Jesper Johansson, a former Microsoft security strategist but now a security program manager at Amazon.com Inc., spelled out how Firefox was as guilty as IE of failing to validate input. In a post that leaned on the metaphor of "glass houses," Johansson showed how Firefox passes potentially malicious URLs to other applications, including the multiple-service instant messaging client Trillian. "Firefox is subject to the exact same flaw that they blame on IE. Firefox also does not escape quotes in URLs before it passes them on to protocol handlers," he said.
Snyder did not credit Johansson by name for alerting Mozilla to the Firefox bug, but she admitted that the flaw should have been spotted. "We should have caught this scenario when we fixed the related problem in 2.0.0.5," she said.
She did not specify when a patch would be issued, but one is in the works, according to an entry in Bugzilla.
Related News and Discussion:
- Hacking Firefox: The secrets of about:config
- Mozilla patches Firefox, slams door on IE zero-day
- Browser Smackdown: Firefox vs. IE vs. Opera vs. Safari
- Preston Gralla: Why Firefox has lost its mojo
Read more about Security in Computerworld's Security Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...