You are here: silicon.com > Software > Malware

Malware

Attack code for old Firefox bug hits the net

Time to upgrade...

Tags: firefox, mozilla, cyber attack flaw, flaw

By Joris Evers

Published: 14 December 2005 08:30 GMT

Computer code that demonstrates how a known flaw in an older version of the Firefox or Mozilla web browsers can be exploited in a potentially crippling attack was published on the web over the weekend.

The vulnerability was fixed in Firefox 1.0.5, released in July, and in Mozilla Suite 1.7.9, according to Mozilla.

The code was published by Aviv Raff, a developer in Israel. Writing in his blog on Sunday he said: "I think it's been enough time for people to upgrade from v1.0.4 of Firefox." Raff's code doesn't do much harm but he notes that it would be easy to turn it into malicious code that commandeers a vulnerable system.

The vulnerability is in the way the web browsers handle JavaScript, according to a Mozilla alert dated 12 July, the day Firefox 1.0.5 was released. An attacker could craft a malicious website that, when accessed by a vulnerable PC, could let a attacker run code on that system without the owner realising it.

Mozilla has released several updates to both Firefox and the Mozilla Suite since July. The latest version of Firefox is 1.5, released late last month. A security vulnerability that could cause the browser to appear to hang has already been pinpointed in that version but Mozilla says it is a minor problem.

In other browser news, Microsoft on Tuesday released a patch that fixes four vulnerabilities in Internet Explorer. The software maker deems two of the flaws "critical". One is already being used to attack IE users, Microsoft said in a bulletin.

Secunia is warning of a security flaw in version 8.01 of the Opera web browsers. Earlier versions may also be affected, the security monitoring company said in an alert on Tuesday. The flaw lies in the way the browser handles mouse clicks in new windows and in how it displays a dialogue box for downloads, according to Secunia's advisory.

The Opera flaw could be exploited to trick people into downloading malicious programs, Secunia said. The company advised people to upgrade to Opera 8.0.2, which has been available since late July.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
PHP Developer, Online Design Agency, Basingstoke - 35k - 40k

Excellent internet skills in using various browsers and search engines Knowledge of browser quirks and variations PHP Developer, Online Design ...

Front End Development / JavaScript / 40k / City of London

Ideally you will have experience with the following: - DHTML (3 years) - JavaScript (3 years) - CSS (3 years) - Cross Browser Development (3 years) ...

Front-End Web Developer (CSS / XHTML /Javascript) - Worcester

You will also be responsible for testing, compatibility of website multi browsers, and SEO. Required Skills: Commercial track record in Front-End ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: