
Users at risk from "moderately critical" hole…
Published: 6 April 2005 09:10 GMT
A flaw has been discovered in the popular open-source browser Firefox that potentially could release sensitive information stored in memory, according to a report by security information company Secunia.
While the flaw is only rated as "moderately critical," the rapid adoption of the open-source browser may put a growing number of users at risk. Prior to the release of version 1.0, downloads of earlier versions of the browser had reached eight million within the first 18 months.
Firefox versions 1.0.1 and 1.0.2 contain the flaw, Secunia said.
The vulnerability stems from an error in the JavaScript engine, according to Secunia. This error can expose arbitrary amounts of heap memory after the end of a JavaScript string. As a result, an exploit may disclose sensitive information in the memory.
"Unlike other browser flaws, this one is not subject to phishing or access to the system. But it can expose sensitive information from other websites you visited and the information you entered there," said Thomas Kristensen, Secunia's CTO.
Mozilla is currently working on a patch, and no known cases have been reported, said a Mozilla spokesman.
Secunia has developed a test that allows users to gauge whether their systems are affected by the vulnerability.
Dawn Kawamoto writes for CNET News.com
Java / .Net Software Developers - cool open source projects (City) Java / J2EE / C# / .NET / C++ With the price of celebrity plastic on the rise and ...
Working within a small top-quality UK-based team, the initial focus will be on driving down the memory requirements while maintaining an ultra-stable ...
Position: Distribution Manager, Flash Memory Salary: $Negotiable, with experience Location: New York Our client, a world leader in innovative ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business
Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...