Opera patches bug, bashes Mozilla
Norwegian browser maker took rival to the woodshed over irresponsible disclosure
Computerworld - Opera Software ASA patched a trio of bugs in its flagship browser yesterday, including one that a company manager used last week to slam rival Mozilla Corp.
The update, dubbed Opera 9.26, plugs three security vulnerabilities. The most serious is rated "highly severe" by the Oslo-based developer and could be used by attackers to dupe the browser into treating image-file comments as script. "This can cause the script to be run in the wrong security context," Opera's advisory read.
But it was another, less-dangerous bug that raised the ire of Claudio Santambrogio, Opera's quality assurance desktop test manager. In a post to a company blog last Thursday, Santambrogio used the flaw to take Mozilla to task.
"Mozilla notified us of one security issue the day before they published their public advisory," said Santambrogio. "They did not wait for us to come back with an ETA for a fix. They kept their bug reports containing the details of the exploits closed to the public for a few days, and now opened most of them to everybody."
The bug, which was one of 11 that Mozilla patched Feb. 7 when it released Firefox 2.0.0.12, could let attackers spoof input fields. Mozilla said that the vulnerability could be used to dupe users into unwittingly uploading malicious code; Opera's advisory agreed.
Although Santambrogio claimed that Mozilla had opened the vulnerability's Bugzilla entry -- and thus disclosed details of the bug before Opera was able to patch -- the entry is currently locked. It is inaccessible even to users with a general Bugzilla account.
Santambrogio seemed to knock Mozilla for not abiding by the unwritten rule of "responsible disclosure," which requires that researchers wait until vendors patch a bug before revealing details of the vulnerability. "Opera is as always committed to not only protecting its users, but to making the Web a safe place. We believe in responsible [emphasis in original] disclosure of vulnerabilities affecting several vendors," he said.
Mozilla said it would not comment on the dustup.
Opera 9.26 can be downloaded from the company's Web site in versions for Windows, Mac OS X and Linux.
Read more about Security in Computerworld's Security Topic Center.
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- A Comprehensive Strategy to Leverage Mobile A successful mobile strategy begins with a common platform for integrating and managing mobile devices and the corporate assets that are stored on...
- IDC - SAP Enterprise Mobility: Bringing a Cohesive Approach to a Complex Market This IDC white paper discusses key mobility trends and examines how SAP's mobile enterprise solutions map to meet organization's mobile requirements.
- The App Happy Enterprise This Computerworld playbook explores key aspects of the enterprise mobile revolution and provides a set of step-by-step directions on how to productively manage...
- Navigating the New Mobile World Over the next five years, companies will evolve to mobile-empowered businesses in three phases, which include extending existing systems, accelerating decisions and responses,...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts