You are here: silicon.com > Software > Security Strategy

Security Strategy

Firefox security update keeps people in the dark

Several bugs fixed, some "high risk"...

Tags: flaw, security, firefox, mozilla

By Joris Evers

Published: 13 July 2005 08:48 GMT

The Mozilla Foundation has fixed several security flaws in its Firefox browser but has left people in the dark about what some of the issues entail.

Firefox 1.0.5, released on Tuesday, patches about 10 bugs in the open source web browser, some of them "high risk", according to Chris Hofmann, director of engineering at Mozilla. High-risk problems typically allow an intruder to commandeer a PC or expose the user's data.

"We have a collection of bug fixes that we have been working on for the last couple of weeks," Hofmann said.

Two of the flaws that have been patched were reported in June by security-monitoring company Secunia, a Mozilla representative said. The group has not released details on the other eight vulnerabilities, even though the software revamp was made available online on Tuesday. Mozilla said it is still working on providing a description of those outstanding security problems.

The update also includes improvements to make Firefox more stable, Mozilla said in its online posting.

Some of the security holes in Firefox were reported by Mozilla community members, helped by the group's bug bounty programme, which provides $500 and a Mozilla T-shirt for finders of critical flaws, Hofmann said.

Most of the flaws would require some user interaction for an attacker to be able to exploit them, Hofmann said. There are no known attacks that use any of the newly fixed problems, he said.

The vulnerabilities reported by Secunia are spoofing flaws, which could let an attacker place malicious content on trusted websites. One problem lies in the way the browser handles frames. The other exists because JavaScript dialogue boxes do not display or include their origin.

Firefox 1.0.5 is the first update to the popular alternative browser since 11 May, when Mozilla released version 1.0.4 to fix three bugs.

Later this week, Mozilla plans to release a new version of its Thunderbird email client. Thunderbird shares some code with Firefox and thus is vulnerable to the same security bugs, Hofmann said. An update to the Mozilla Suite is also scheduled to appear soon.

An alert mechanism in Firefox is designed to let people know that an update is available. They will have to download the full new browser, which is about 4.8MB in size. The next version of Firefox, release 1.1 due in August or September, will have a more streamlined patching mechanism that will let people download just the fixes, Hofmann said.

Since the debut of Firefox 1.0 in November, its usage has grown at a rapid pace. Security has been a main selling point for Firefox over rival Microsoft's Internet Explorer, which has begun to see its market share dip slightly - for the first time in a number of years. Firefox US usage share reached nearly seven per cent at the end of April, according to tracking company WebSideStory.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Quality Assurance Specialist- Digital Agency

Skills needed- Knowledge of HTML, CSS, and XML, to help diagnose errors and suggest fixes Cross-browser expertise, in testing and identifying fixes ...

CSS / HTML Front End Developer Publishing London

s growing portfolio of online products.You will take charge and enhance all of the products across the company (including blogs), ensuring that your ...

QA / Software Tester - Derby, East Midlands

Understand and interpret software bugs, software enhancements or modifications that are reported internally or from customers and ensure that the ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: