Mozilla Issues 'Critical' Security Fixes
By Jay Lyman
LinuxInsider
11/10/06 4:00 AM PT
Although the vast majority of Internet attacks are aimed at Microsoft's Internet Explorer, due to its share of the browser market and IE's tight coupling with Windows, some do target Firefox code. Browser-based attacks have become common, and the trend is fueled by "point and click" exploit-and-attack methods, as well as the increasing availability of attack code.

What’s Linux with a Lineage?
Verio Linux VPS delivers root access, advanced FairShare technology for better performance, and support that's actually supportive. It's all from Verio, the Virtual Private Server technology pioneer with over 500,000 customers. Test-drive Linux VPS here.
It's unclear whether more serious attention from
attackers is on the way, but even if that should be the case, Mozilla will have certain advantages over Microsoft in dealing with such problems.
"It's going to be easier to manage and provide a more rapid
response," VeriSign (Nasdaq: VRSN)
iDefense
Rapid Response Team Director Ken Dunham
told LinuxInsider. That's because Firefox has a modular design with fewer lines of code and fewer interdependencies than Explorer.
Critical Fixes
The three patches that Mozilla issued this week were for security issues it deemed "critical." However, none of the vulnerabilities they address affect the latest version of the Firefox 2.0 browser.
The first fix covered a flaw affecting Firefox, Thunderbird and
SeaMonkey software that would allow running script to be recompiled. The
second vulnerability, affecting the same three software products, could allow forgery of an RSA signature, Mozilla said.
The third issue, which affects the same applications, could cause a
computer crash with evidence of memory corruption, Mozilla said.
Attacks Underway
Although the vast majority of Internet
attacks are aimed at IE, due to its share of the browser market and its tight
coupling with Windows, some do target Firefox code, according to Dunham.
Browser-based attacks have become common, and the trend is fueled by "point and click" exploit-and-attack methods, as well as the increasing availability of attack code.
In addition to high-profile attacks reminiscent of yesterday's worm
outbreaks, there are new tactics that can
quickly turn even moderate or less critical vulnerabilities into threats
for IT organizations, Dunham noted.
Open Defense
Although Firefox's attractiveness to attackers may increase as the browser's market share approaches 20 percent, it is still relatively secure, IT-Harvest Chief Research Analyst Richard Stiennon told LinuxInsider.
"To date, I haven't seen any sign of targeting [Firefox]," he said.
Mozilla's open
source code, which allows both good guys and bad guys to search out
holes, has proven to be an advantage rather than a security liability for Firefox, Stiennon said.
"The more we hear about things Microsoft is doing now in the security
space, we realize how great it is to have total transparency in the
code," he remarked.