Welcome | Log In
Security

Firefox Vulnerability Puts Sensitive Information at Risk

Print Version
E-Mail Article
Reprints

Secunia has released an online test to allow Firefox and Mozilla users to determine if they are affected by the bug. The advisory said the immediate solution is to disable JavaScript support.


Verio MPS Solutions
Verio managed server solutions deliver the power and flexibility of a dedicated server at a fraction of the price. Learn more about how Verio gives you increased control, scalability, uptime, and performance.

A vulnerability has been discovered in the Firefox Web browser that could be exploited by malicious people to gain knowledge of potentially sensitive information, according to an advisory from security research firm Secunia More about Secunia.

The vulnerability comes less than six weeks after the Mozilla Foundation More about Mozilla Foundation released a security update to the Firefox browser that included several fixes to guard against spoofing and arbitrary code execution.

JavaScript Error

"The vulnerability is caused due to an error in the JavaScript engine, as a 'lambda' replace exposes arbitrary amounts of heap memory after the end of a JavaScript string," said the Secunia advisory.

The vulnerability has been confirmed in versions 1.0.1 and 1.0.2. Other versions may also be affected.

Secunia has released an online test to allow Firefox and Mozilla users to determine if they are affected by the bug. The advisory said the immediate solution is to disable JavaScript support Linux MPS Pro - Focus on Your Business - Not Your IT Infrastructure. $599.95/month. Click to learn more..

Firefox Versus Internet Exlporer

Web vulnerabilities are not at all unusual, evidenced by Secunia's deep online library of security advisories about Firefox, Microsoft's (Nasdaq: MSFT) More about Microsoft Internet Explorer, Apple's (Nasdaq: AAPL) Consolidate Mac Servers. Run Windows Server on your Mac. Watch a Demo or Download a Trial. More about Apple Safari and others.

In fact, Jupiter Research analyst Joe Wilcox told TechNewsWorld that vulnerabilities are just "part of the ballgame."

"Flaws will be found because flaws exist and that's going to be true for any Web browser," Wilcox said. "The real question over time is whether the Mozilla folks can keep up with finding problems and then deploying patches in the most efficient manner."

Microsoft's Advantage

That, said Wilcox, is where Microsoft has an advantage in the marketplace. Microsoft has a team dedicated to looking for vulnerabilities, developing patches and distributing them while Firefox has limited resources.

"Just think of Windows Update, for example, and the amount that Microsoft invested in that infrastructure over many years," Wilcox said. "That's a very powerful distribution for getting patches out as quickly and efficiently as possible Firefox doesn't have anything like that."

Secunia's online test for the bug is available via its Web site.

Social Networking Toolbox:
Talkback: Join the Discussion.
Re: Firefox Vulnerability Puts Sensitive Information at Risk
bugmenot
Posted 2005-04-06
Firefox Patched. ...
Re: Firefox Vulnerability Puts Sensitive Information at Risk
Justinus
Posted 2005-04-05
Also, what the author stating about the advantage of Microsoft. It is only the "fact," ...
Inaccuracies in the article
kazriko
Posted 2005-04-05
The comment about no equivalent to Windows Update from Jupiter research is mostly incorrect. ...

Print Version E-Mail Article Reprints More by Jennifer LeClaire   RSS

Related Resources

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
  WiFi Hotspot Locator
City or Zip/Postal Code:
Country/Region:
ECT News Network Information
Locate Products and Services
Corporate
Reader Services
ECT News Network