You are here: silicon.com > Software > Malware

Malware

Security flaw found in Firefox

Users at risk from "moderately critical" hole…

By Dawn Kawamoto

Published: 6 April 2005 09:10 BST

A flaw has been discovered in the popular open-source browser Firefox that potentially could release sensitive information stored in memory, according to a report by security information company Secunia.

While the flaw is only rated as "moderately critical," the rapid adoption of the open-source browser may put a growing number of users at risk. Prior to the release of version 1.0, downloads of earlier versions of the browser had reached eight million within the first 18 months.

Firefox versions 1.0.1 and 1.0.2 contain the flaw, Secunia said.

The vulnerability stems from an error in the JavaScript engine, according to Secunia. This error can expose arbitrary amounts of heap memory after the end of a JavaScript string. As a result, an exploit may disclose sensitive information in the memory.

"Unlike other browser flaws, this one is not subject to phishing or access to the system. But it can expose sensitive information from other websites you visited and the information you entered there," said Thomas Kristensen, Secunia's CTO.

Mozilla is currently working on a patch, and no known cases have been reported, said a Mozilla spokesman.

Secunia has developed a test that allows users to gauge whether their systems are affected by the vulnerability.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Technical Architect (Open Source), Berkshire (optional home working)

Working with a variety of clients you will work with a range of technologies and products, with particular emphasis on delivering the benefits of ...

APPLICATIONS SUPPORT - OPEN SOURCE - MILTON KEYNES - SALARY

Strong background in open source languages? Then read on New opportunity is immediately available for an experienced applications support ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: