Mozilla Patches Firefox Flaw
Workaround will prevent exploits that allow remote control of users' systems through browser bug.
Robert McMillan, IDG News Service
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
The Mozilla Foundation has released a workaround for a critical buffer overflow vulnerability in the Firefox browser that was first made public last Friday.
By Friday afternoon, Mozilla developers had posted a software patch and instructions for a workaround, both of which disable the buggy Firefox feature.
Open to Attack
The vulnerability, which was reported by security researcher Tom Ferris to the Mozilla team earlier this week, concerns the International Domain Name (IDN) feature that Mozilla products use to process Web pages that do not use Latin alphabet characters in their names.
Links pointing to a host with a long name composed entirely of dashes can be crafted so that Firefox will execute arbitrary code of an attacker's choosing, meaning that an attacker theoretically could use the flaw to take control of a user's machine.
No code that actually exploits this vulnerability has yet been seen, but all versions of Mozilla Firefox and the Mozilla Suite are affected, according to the Mozilla team. The vulnerability even includes version 1.5 Beta 1 (Deer Park Alpha 2), which was released on Thursday.
"It's something we take seriously because it could be used for bad things," said Mike Schroepfer, director of engineering with the Mozilla Foundation.
Solid Fix Pending
Because both the patch and the workaround simply disable IDN, users who require the feature to visit international Web sites should stick to visiting Web sites they know and trust until the problem is actually repaired in the browser, Schroepfer said.
When that will happen remains unknown. "We're determining that now," he said.
Ferris described the flaw in his Security Protocols Web site and on the Full Disclosure security mailing list last week. He said the problem is caused by a bug in the code Firefox uses to process HTML (Hypertext Markup Language) links in Web pages.
In August, Ferris reported a critical flaw in fully patched versions of Microsoft Internet Explorer 6 running on Windows XP Service Pack 2. The flaw was acknowledged by Microsoft, but in that instance, Ferris did not reveal any details of the flaw or how it could be exploited.
Peter Sayer of the IDG News Service contributed to this report.
PCW Download Guide
Laptop Showcase
Related Browsers & Add-Ons Articles
- Quick Fix for Firefox 3 Bug with Yahoo Mail If you're missing scrollbars in Yahoo Mail, here's how to get them back.
- Apple: Forget ICards, Try Mail This June's Worldwide Developers Conference saw Apple unveil the iPhone 3G, firm up its iPhone 2.0 plans, offer a brief peek...
- Ease the Safari-to-iTunes Lyric Pasting Task If you enjoy having lyrics with your music in iTunes, you're probably familiar with the tools available to collect those...
- Bugs & Fixes: ITunes' CD Mounting Bug Most often, when Apple releases an minor update to one of its applications, such as iTunes, its purpose is to provide bug...
- Yelp for IPhone You'd be hard pressed to find a more opinionated, verbose, and downright catty group than the citizen reviewers on...
Best Prices on Security Software
Norton Internet Security 2008Price: $19.40
Internet Security 2008 - 3-User (Full Product, PC)Price: $12.99
Norton 360Price: $32.99
Norton 360 2.0 ( PC)Price: $40.00
Internet Security Suite 2008 - 3-UserPrice: $18.95
Internet Security 7.0 - 3-UsersPrice: $19.95
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- The Future Sales Force - A Consultative Approach This white paper discusses the challenges of selling complex products and services, and the new skill sets sales professionals must employ in today's evolving market.





"Mozilla Patches Firefox Flaw" Comments