Opera patches bug, bashes Mozilla
Norwegian browser maker took rival to the woodshed over irresponsible disclosure
The update, dubbed Opera 9.26, plugs three security vulnerabilities. The most serious is rated "highly severe" by the Oslo-based developer and could be used by attackers to dupe the browser into treating image-file comments as script. "This can cause the script to be run in the wrong security context," Opera's advisory read.
But it was another, less-dangerous bug that raised the ire of Claudio Santambrogio, Opera's quality assurance desktop test manager. In a post to a company blog last Thursday, Santambrogio used the flaw to take Mozilla to task.
"Mozilla notified us of one security issue the day before they published their public advisory," said Santambrogio. "They did not wait for us to come back with an ETA for a fix. They kept their bug reports containing the details of the exploits closed to the public for a few days, and now opened most of them to everybody."
The bug, which was one of 11 that Mozilla patched Feb. 7 when it released Firefox 188.8.131.52, could let attackers spoof input fields. Mozilla said that the vulnerability could be used to dupe users into unwittingly uploading malicious code; Opera's advisory agreed.
Although Santambrogio claimed that Mozilla had opened the vulnerability's Bugzilla entry -- and thus disclosed details of the bug before Opera was able to patch -- the entry is currently locked. It is inaccessible even to users with a general Bugzilla account.
Santambrogio seemed to knock Mozilla for not abiding by the unwritten rule of "responsible disclosure," which requires that researchers wait until vendors patch a bug before revealing details of the vulnerability. "Opera is as always committed to not only protecting its users, but to making the Web a safe place. We believe in responsible [emphasis in original] disclosure of vulnerabilities affecting several vendors," he said.
Mozilla said it would not comment on the dustup.
Opera 9.26 can be downloaded from the company's Web site in versions for Windows, Mac OS X and Linux.
Read more about Security in Computerworld's Security Topic Center.
- Best Practices for Securing Hadoop Historically, Apache Hadoop has provided limited security capabilities. To protect sensitive data being stored and analyzed in Hadoop, security architects should use a...
- Top Tips for Securing Big Data Environments: Why Big Data Doesn't Have to Mean Big Security Challenges Organizations must come to terms with the security challenges they introduce. As big data environments ingest more data, organizations will face significant risks...
- 5 Ways Dropbox for Business Keeps Your Data Protected Protecting your data isn't a feature on a checklist, something to be tacked on as an afterthought. Download here to find out how...
- The Keys to Securing Data in a Collaborative Workplace Losing data is costly. IT professionals have spent years learning how to protect their organizations from hackers, but how do you ward off...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!