Home › News › Industry News
Extremely critical Firefox flaws
Because proof-of-concept code has been leaked -- as were the vulnerabilities -- before a patch was ready, Mozilla recommended that Firefox users either disable JavaScript or lock down the browser so it doesn't install additional software, such as extensions or themes, from Web sites.
The vulnerabilities were discovered by a pair of security researchers, who had notified Mozilla earlier in the month, but were keeping mum until a patch was written. However, details of the vulnerabilities were leaked by someone close to one of the researchers.
It appears that it is possible to trick the browser into thinking a download is coming from one of the by-default sites permitted to install software automatically: addons.mozilla.org or update.mozilla.org. Changes have been made to the Mozilla update site to try to minimise any potential for damage, however the problem will not be fixed properly until we are given Firefox 1.0.4.
Related Stories
User Comments (4)
Post a comment|
smtkr
on May 9, 2005 8:37 PM |
How to run malicious code in Linux:1. Log in as root2. Run malicious script.I still feel very safe. |
|
phantasm66
on May 10, 2005 3:14 AM |
Erm, this news post is about Firefox, and a flaw in that. |
|
Mictlantecuhtli
on May 10, 2005 6:14 AM |
I enable "Allow web sites to install software" only when I'm going to install an extension or a plugin, and disable it after installation. Isn't that just common sense? |
|
phantasm66
on May 10, 2005 9:37 AM |
Yes, but 99.9% of people in the world now who are using the internet don't have common sense. Probably about 40% of them are even pleased to have been able to switch the computer on, find the internet browser and navigate to the page. You are thinking like a computer enthusiast / expert not a member of the public, who like it or lump it use computers and the net all the time now. |
Most Popular
| Trending | Featured |
-
iOS 5.1.1 untethered jailbreak tool released, supports 4S, iPad 3
-
After five days, Facebook ranks as worst IPO flop of the decade
-
Rumor: Windows 8 RC will launch June 1, will ship with Adobe Flash
-
Diablo III becomes the fastest-selling PC game in history
-
Rumor: AMD "Piledriver" FX CPU production to begin Q3 2012
Editors' Storage Picks
Subscribe to TechSpot
Get free exclusive content, learn about new features and tech breaking news.