also @ TechSpot: Fair Labor Association begins inspections of Foxconn at Apple's request
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Begin your free trial now Pay-as-you-go options starting at $10/user/month

Security flaw found in Mozilla browsers

Thread Tools Search this Thread
  #1  
Old 07-09-2004
Julio's Avatar
TechSpot Executive Editor
 
Location: Ecuador
Member since: Feb 2002, 5,352 posts
System specs
Security flaw found in Mozilla browsers

Microsoft's Internet Explorer has been hardly critiziced over the past few months given the impressive number of security holes found which has kept increasing as times passes. Rest assured however no piece of software is perfect and with all the attention PC security is getting nowadays, it came as no surprise a new security flaw discovered in Mozilla browsers caught the big headlines earlier today:

"Branches have been created for three of mozilla.org's latest releases, in order to fix an external Windows protocol handler bug. The fix involves disabling the shell: protocol handler, which was found to enable pages to run executables on Windows via a link. Builds should officially be available shortly, and there will also be an XPI offered to disable the pref. Alternatively, you can set the pref network.protocol-handler.external.shell in about:config to false to remove the exploit."

Patched versions of Mozilla 1.7.1 and Firefox 0.9.2 have been released now, also there's the option of downloading a XPI patch to that disables the shell: protocol handler.
  #2  
Old 07-09-2004
Didou's Avatar
Bowtie extraordinair!
 
Location: Brussels, Belgium
Member since: Feb 2002, 5,895 posts
System specs
You can also find the patch HERE.
  #3  
Old 07-09-2004
Newcomer, in training
 
Location: Laval, Qc, Canada
Member since: Aug 2003, 18 posts
Glad to see they are patching it both way(new release and patch) So new users are patched right away instead of downloading 2 things!
  #4  
Old 07-09-2004
Godataloss's Avatar
TechSpot Booster
 
Location: Lorain, Ohio
Member since: Oct 2003, 501 posts
I'm pretty sure this is my fault
Since I finally allowed firefox to be my default browser yesterday, it only makes sense that it would start to get holes punched in it
:unch:firefox
  #5  
Old 07-09-2004
Arris's Avatar
TechSpot Evangelist
 
Location: Aberdeen, Scotland, UK
Member since: Feb 2002, 4,083 posts
System specs
Well I still feel good about being a long term Opera user (until it gets its flaws searched out).
  #6  
Old 07-09-2004
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
This problem only affects Windows, not other OSes.

"Mozilla 1.7.1, Mozilla Firefox 0.9.2 and Mozilla Thunderbird 0.7.2 contain no new features other than a preference change that disables the shell: protocol handler."

"Some may find it notable that a patch was issued less than forty-eight hours after this bug was filed."

"On July 7 (yesterday) a security vulnerability affecting browsers for the Windows operating system was posted to Full Disclosure, a public security mailing list. On the same day, the Mozilla security team confirmed the report of this security issue affecting the Mozilla Application Suite, Firefox, and Thunderbird and discussed and developed the fix at Bugzilla bug 250180. We have confirmed that the bug affects only users of Microsoft's Windows operating system. The issue does not affect Linux or Macintosh users.

Today, the Mozilla team released a configuration change which resolves this problem by explicitly disabling the use of the shell: external protocol handler."

So there you have it, the Mozilla team fixes a security issue pointed out within 48 hours. Microsoft gets pointed out security issues dating back (+2 years in some cases) months & fail to fix them, instead pointing out they wouldn't classify it as a security problem, or in many cases only fixing 1 particular method of exploiting a hole, rather than fixing the root problem itself.
  #7  
Old 07-09-2004
Federelli's Avatar
TechSpot Booster
 
Location: Buenos Aires, Argentina
Member since: Mar 2002, 382 posts
So this is more a Windows flaw than it's a mozilla one? ...
I'm glad they patched right away
  #8  
Old 07-09-2004
---agissi---'s Avatar
TechSpot Paladin
 
Location: Montana
Member since: Mar 2002, 2,303 posts
A

Aha

Ahahahah
  #9  
Old 07-09-2004
DigitAlex's Avatar
TechSpot Paladin
 
Location: Brussels, Belgium
Member since: Jul 2002, 583 posts
yes, acutally the IE and Mozilla flaws are a huge Windows security hole, the shell: handler provided to the browsers.
  #10  
Old 07-09-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
Quote:
Originally posted by Godataloss
I'm pretty sure this is my fault
Since I finally allowed firefox to be my default browser yesterday, it only makes sense that it would start to get holes punched in it
:unch:firefox
LOL!

That's what I think has happened to me as well.
Closed Thread

Similar Topics
Topic Replies Forum
WinZip has security flaw fix 0 General Discussion
Exchange Server 5.5 security flaw found 0 General Discussion
Security hole found in Mozilla browser 18 General Discussion
ANOTHER Internet Explorer Flaw Found 7 General Discussion
Microsoft XP Security Flaw 0 General Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 09:37 AM.