Welcome | Sign In
LinuxInsider.com
Applications

Mozilla Issues Firefox Fix

Print Version
E-Mail Article
Reprints
Mozilla Issues Firefox Fix

In all, the Firefox 1.0.5 addressed 12 vulnerabilities, including Javascript origin spoofing, content-generated event vulnerabilities, and a possible exploitable crash in InstallVersion.compareTo().


Crystal Reports - Discover the Latest Innovations.
Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.

Mozilla on Tuesday released the latest version of its popular Firefox open-source Web browser and its e-mail client. The release marks the second time in eight days the company has issued fixes.

Firefox 1.0.6 is a stability update that restores API compatibility for extensions and Web applications that did not work in Firefox 1.0.5. Firefox 1.0.5 is the security update released last week that addressed several bugs and made improvements to the software's stability, according to Mozilla.

In all, the Firefox 1.0.5 addressed 12 vulnerabilities, including Javascript origin spoofing, content-generated event vulnerabilities, and a possible exploitable crash in InstallVersion.compareTo().

Security Focus

Some of those bugs were "high risk" and could allow a malicious code writer to overtake a PC or expose a user's data. The Mozilla community's bug bounty program helped uncover some of the security holes. The bug finders each received US$500 and a Mozilla T-shirt.

Firefox is not alone. Other popular Web browsers, including Microsoft's (Nasdaq: MSFT) Internet Explorer and Apple's (Nasdaq: AAPL) Safari, also have a list of fixed flaws to their credit. Michael Sutton, director of iDefense Labs, the company's vulnerability research arm, told LinuxInsider there are several reasons why we see so many browser flaws.

"Certainly there is always a race to beat the competition," Sutton said. "Browser makers want to get the product out the door and, historically, security has not been as important in the quality assurance cycle as it should have been."

However, Sutton said because end users are placing a greater emphasis on the value of security, vendors are now being forced to make it a priority.

Critical Apps

Analysts say that browsers have become critical inroads into corporate technology infrastructure, and therefore, browser security flaws are far riskier than applications that sit on the desktop.

"Browsers are not just browsers anymore. They have all kinds of functionality. The idea is to increase that functionality all the time," Sutton said. "Look at what Internet Explorer does today versus what it did five years ago. Any time you add increased functionality there is a greater likelihood that you are going to introduce vulnerabilities into the product."

Mozilla plans to release Firefox 1.1 in August or September. That version will allow users to download the fixes through an integrated system update that issues small-sized upgrade files. Firefox 1.1 also includes a feature that caches previously visited pages in the memory to allow faster displays when users click back and forward navigation buttons.

E-Mail Improvements

Also this week, Mozilla released Thunderbird 1.0.6, a stability update that restores API compatibility of extensions that did not work in Thunderbird 1.0.5. Thunderbird 1.0.5 shipped out in early July to fix several security flaws, including XHTML node spoofing, possible exploitable crashes and missing install object instance checks.

Thunderbird 1.0.6 is fixing extensions that 1.0.5 unintentionally broke, according to the MozillaZine blog. Specifically, Enigmail PGP, security software that enables e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse encryption and other features, does not work in the 1.0.5 release.


Print Version E-Mail Article Reprints More by Jennifer LeClaire


More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network