Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Firefox flaw found: Remote exploit possible

The vulnerability affects the new beta version released today
 

Sign up to receive Security Resource Alerts

September 9, 2005 (IDG News Service) -- Computers running the Firefox browser could be open to remote attack as a result of a buffer overflow vulnerability reported today by security researcher Tom Ferris.
Vulnerable versions of Firefox include all those up to 1.06, and even the just-released Version 1.5 Beta 1 (Deer Park Alpha 2), Ferris wrote in a posting to his Web site, Security Protocols, and to the Full Disclosure security mailing list just after 1 a.m. EDT today.
Ferris said he reported the bug to staff at the Mozilla Foundation, the organization behind the Firefox browsers, on Sept. 4, but had no idea whether the foundation is working on a fix for the problem.
The problem is caused by a bug in the code Firefox uses to process HTML links in Web pages, Ferris said. Links pointing to a host with a long name composed entirely of dashes can be crafted so that Firefox will execute arbitrary code of an attacker's choosing.
Mozilla officials said today that they learned of the issue on Tuesday and are already working on a patch. "We have a preliminary patch for part of the problem, and are in the process of developing a comprehensive solution that will appear in a upcoming release," said Michael Schroepfer, Mozilla's head of engineering. He was not sure when the patch would be released.
Last month, Ferris reported a critical flaw in fully patched versions of Microsoft Corp.'s Internet Explorer 6 running on Windows XP Service Pack 2. The flaw was acknowledged by Microsoft, but in that instance, Ferris did not reveal any details of the flaw or how it could be exploited.
Computerworld's Sharon Machlis and Todd Weiss contributed to this report.


Reprinted with permission from

IDG.net
Story copyright 2008 International Data Group. All rights reserved.


Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"I had a chuckle when I read Gregg Keizer's article "..." Read more...
"In Monday's IT Blogwatch, Richi Jennings watches bots compete in the 18th Loebner Prize for Artificial Intelligence. Not to mention..." Read more...
Read more Security posts or See all Blogs
'Experimental' security fix is malware, Microsoft says
Top security suites fail exploit tests
Gartner: Financial meltdown may mean hiring freezes, staffing cuts for IT
More top stories...
Microsoft readies first attack forecast
NASA follows Mars successes with plans for $2B super rover
Microsoft sticks with 'Windows 7' for next OS
How bad? 'I thought I was going to throw up,' Jennifer Brunner recalls.
Think your project's off track and over budget? Learn a lesson or two from these infamous project flameouts.
In our hands-on testing, the new Xohm WiMax network from Sprint was fast and smooth -- but for now, you have to be in Baltimore to get it.
College student David Kernell allegedly broke into a middle school server eight years ago, according to a former teacher.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
The Enterprise Search Zone
Software as a Service Zone
The Security Zone

Ads by TechWords

See your link here
Moving to Windows Vista: The Promise, The Reality
Moving to Windows Vista: The Promise, The Reality
View this exclusive webcast today!
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Quick Sizing Guide for SAS Grid Running on HP BladeSystems and EVA Storage
Download this white paper today!
(Source: HP) Designed for CIOs, IT managers, data center managers and grid computing architects seeking to improve performance, SAS Grid Computing on the HP BladeSystem c-Class helps accelerate growth and mitigate risks with a simplified, consolidated infrastructure that's agile enough to efficiently handle change. SAS Grid Manager on HP BladeSystem can lower costs through automation, virtualization and improved IT efficiency.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Business Transaction Management: Facilitating the Management of Virtual Environments
Quick Sizing Guide for SAS Grid Running on HP BladeSystems and EVA Storage
Prudential Financial protects its brand with Symantec Data Loss Prevention solutions
View more whitepapers