also @ TechSpot: Weekend Open Forum: Google Chrome OS and the future of cloud computing
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > News and Links from Around the Web > Old Frontpage News & Comments

Security flaw found in Mozilla browsers

 
Bookmark Thread Tools
  #1  
Old 07-09-2004
Julio's Avatar
TechSpot Elite
 
Location: Ecuador
Member since: Feb 2002, 4,721 posts
System specs
Security flaw found in Mozilla browsers

Microsoft's Internet Explorer has been hardly critiziced over the past few months given the impressive number of security holes found which has kept increasing as times passes. Rest assured however no piece of software is perfect and with all the attention PC security is getting nowadays, it came as no surprise a new security flaw discovered in Mozilla browsers caught the big headlines earlier today:

"Branches have been created for three of mozilla.org's latest releases, in order to fix an external Windows protocol handler bug. The fix involves disabling the shell: protocol handler, which was found to enable pages to run executables on Windows via a link. Builds should officially be available shortly, and there will also be an XPI offered to disable the pref. Alternatively, you can set the pref network.protocol-handler.external.shell in about:config to false to remove the exploit."

Patched versions of Mozilla 1.7.1 and Firefox 0.9.2 have been released now, also there's the option of downloading a XPI patch to that disables the shell: protocol handler.
  #2  
Old 07-09-2004
Didou's Avatar
TechSpot Evangelist
 
Location: Brussels, Belgium
Member since: Feb 2002, 5,845 posts
System specs
You can also find the patch HERE.
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 07-09-2004
Newcomer, in training
 
Location: Laval, Qc, Canada
Member since: Aug 2003, 18 posts
Glad to see they are patching it both way(new release and patch) So new users are patched right away instead of downloading 2 things!
  #4  
Old 07-09-2004
Godataloss's Avatar
TechSpot Enthusiast
 
Location: Lorain, Ohio
Member since: Oct 2003, 501 posts
I'm pretty sure this is my fault
Since I finally allowed firefox to be my default browser yesterday, it only makes sense that it would start to get holes punched in it
:unch:firefox
  #5  
Old 07-09-2004
Arris's Avatar
TechSpot Evangelist
 
Location: Aberdeen, Scotland, UK
Member since: Feb 2002, 3,033 posts
Well I still feel good about being a long term Opera user (until it gets its flaws searched out).
  #6  
Old 07-09-2004
TS | Thomas's Avatar
TechSpot Addict
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
This problem only affects Windows, not other OSes.

"Mozilla 1.7.1, Mozilla Firefox 0.9.2 and Mozilla Thunderbird 0.7.2 contain no new features other than a preference change that disables the shell: protocol handler."

"Some may find it notable that a patch was issued less than forty-eight hours after this bug was filed."

"On July 7 (yesterday) a security vulnerability affecting browsers for the Windows operating system was posted to Full Disclosure, a public security mailing list. On the same day, the Mozilla security team confirmed the report of this security issue affecting the Mozilla Application Suite, Firefox, and Thunderbird and discussed and developed the fix at Bugzilla bug 250180. We have confirmed that the bug affects only users of Microsoft's Windows operating system. The issue does not affect Linux or Macintosh users.

Today, the Mozilla team released a configuration change which resolves this problem by explicitly disabling the use of the shell: external protocol handler."

So there you have it, the Mozilla team fixes a security issue pointed out within 48 hours. Microsoft gets pointed out security issues dating back (+2 years in some cases) months & fail to fix them, instead pointing out they wouldn't classify it as a security problem, or in many cases only fixing 1 particular method of exploiting a hole, rather than fixing the root problem itself.
  #7  
Old 07-09-2004
Federelli's Avatar
TechSpot Enthusiast
 
Location: Buenos Aires, Argentina
Member since: Mar 2002, 382 posts
So this is more a Windows flaw than it's a mozilla one? ...
I'm glad they patched right away
  #8  
Old 07-09-2004
---agissi---'s Avatar
TechSpot Paladin
 
Location: Uranus
Member since: Mar 2002, 2,122 posts
A

Aha

Ahahahah
  #9  
Old 07-09-2004
DigitAlex's Avatar
TechSpot Paladin
 
Location: Brussels, Belgium
Member since: Jul 2002, 583 posts
yes, acutally the IE and Mozilla flaws are a huge Windows security hole, the shell: handler provided to the browsers.
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 07-09-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,703 posts
Quote:
Originally posted by Godataloss
I'm pretty sure this is my fault
Since I finally allowed firefox to be my default browser yesterday, it only makes sense that it would start to get holes punched in it
:unch:firefox
LOL!

That's what I think has happened to me as well.
 

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
WinZip has security flaw fix Old Frontpage News & Comments 0 09-07-2004 03:49 PM
Exchange Server 5.5 security flaw found Old Frontpage News & Comments 0 08-11-2004 03:39 PM
Security hole found in Mozilla browser News and Links from Around the Web 18 07-10-2004 10:54 AM
Microsoft haunted by old IE security flaw Old Frontpage News & Comments 0 06-30-2004 02:31 PM
Mozilla riddled with security holes News and Links from Around the Web 0 11-05-2002 12:36 PM


All times are GMT -4. The time now is 08:27 AM.