You are here: silicon.com > Software > Security Strategy

Security Strategy

Exploit fear grows around Firefox flaw

Code appears on the web...

Tags: exploit, firefox

By Joris Evers

Published: 7 July 2005 08:49 GMT

Computer code that could be used to attack systems with older versions of Firefox has been released on the internet, security experts have warned.

The exploit code takes advantage of a security vulnerability in Firefox 1.0.1 and earlier versions of the open source web browser, the French Security Incident Response Team, or FrSIRT, said in an advisory posted on Wednesday.

The bug exists because of an error in the way the older versions of Firefox handle GIF images. An attacker could gain control of a PC by luring the user to a web page or sending an email containing a specially crafted image, according to FrSIRT, which rates the issue "critical".

Only Firefox 1.0.1 and earlier are vulnerable. The image-parsing problem was fixed in Firefox 1.0.2, which was released in March. Since then, two more Firefox updates have been released, mostly to address security issues. The most recent version is Firefox 1.0.4, which was released in May.

Because the security bug was quashed more than three months ago, the exploit release is less of a concern, said Michael Sutton, a lab director at security company iDefense. "Given the length of time during which patches have been available, I would consider the release of this exploit to be a credible threat but not critical," he said.

A representative for the Mozilla Foundation, the maker of Firefox, said most of the browser's users have upgraded to version 1.0.4. Mozilla encourages people to check for updates regularly and update their browser when a new version is available, the representative said.

Since the debut of Firefox 1.0 in November, its usage has grown at a rapid pace. Security has been a main selling point for Firefox over Microsoft's rival Internet Explorer. The number of downloads of the software is close to passing the 70 million mark, according to the download counter Spread Firefox website. That total represents downloads of all versions, so it doesn't necessarily represent individual users.

Firefox has demonstrated that the mature web browser market, dominated by Internet Explorer, can be shaken up. IE has begun to see its market share dip slightly - a first in a number of years. Firefox US usage share reached nearly seven per cent at the end of April, according to tracking company WebSideStory.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Java / WebObjects Developer / Java / WebObjects Programmer - London

Java / WebObjects Developer / Java / WebObjects Programmer - London Location: London Salary: 35,000 - 48,000 Company: People's IT Job type: Permanent ...

Application Access Engineer

You MUST be SC cleared Skills mandatory: Enterprise scale Infrastructure Topologies and Architectures; Enterprise scale application deployment ...

Web Developer Co Clare

Keywords:Web developer web designer web Specialist front end intranet job role career Co Clare Shannon Ennis Clare Limerick west coast west-coast ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: