You are here: silicon.com > Software > Security Strategy

Security Strategy

Mozilla to release Firefox update to fix flaws

Version 1.0.7 on the way "shortly"

Tags: flaw, firefox, mozilla

By Joris Evers

Published: 15 September 2005 08:25 GMT

The Mozilla Foundation plans to "shortly" release new versions of its Firefox and Mozilla web browsers to address a recently disclosed serious security bug as well as several additional flaws, a representative said on Wednesday.

The decision for new, so-called point releases was made after the disclosure last week of a problem in the way the browsers handle International Domain Names, or IDNs - web addresses that use international characters. The vulnerability could let attackers secretly run malicious software on users' PCs. Hackers have been working on exploits for the flaw.

Mike Schroepfer, director of engineering at the Mozilla Foundation, said: "As soon as we got the report that users might be impacted, we began evaluating our options." Firefox version 1.0.7 and Mozilla version 1.7.12, which fix the IDN flaw, are now being tested, he said. "We're releasing as soon as we possibly can."

The testing process is to make sure the updates don't introduce any compatibility problems, he said.

In addition to patching the IDN bug, the new releases include one functionality fix and a handful of fixes for yet undisclosed security problems, Schroepfer said.

The Mozilla Foundation, which distributes and co-ordinates the development of Firefox and Mozilla, responded swiftly to the IDN bug disclosure last week and within 24 hours provided a temporary fix. Though the fix disables support for IDNs, the new updates that are now being tested will actually fix the vulnerability and re-enable IDNs, Schroepfer said.

IDNs have caused trouble for Mozilla in the past. A Firefox security update in February fixed a flaw that would allow domain spoofing using the special domain names.

As the Mozilla Foundation and the open source community were working on fixing the IDN flaw, the discoverer of that bug reported yet another issue with Firefox. Security researcher Tom Ferris on Wednesday said that Firefox1.5 beta 1 is vulnerable to a problem similar to the IDN bug he disclosed last week.

Even with the fix that disables IDN installed, a buffer overflow vulnerability exists in Firefox 1.5 beta 1, Ferris wrote on his Security Protocols website. The problem is a variant of the original IDN bug, he wrote.

Buffer overflows are a commonly exploited security problem. They occur when a program allows data to be written beyond the allocated end of a buffer in memory. A computer can be made to execute potentially malicious code by feeding in extra data that is designed to flood over the buffer.

Firefox 1.5 beta 1 was released last week and is a test version of a new Firefox browser due out by the year's end.

The Mozilla Foundation is investigating Ferris' latest report, Schroepfer said. "At this time we're not sure whether it is a vulnerability," he said.

The latest problem occurs only in the beta release, which is meant for testing only and typically has bugs. The beta has been downloaded about 500,000 times, according to Schroepfer.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Software Project Manager - London - Up to 65K

Software Project Manager London SE1 Up to 65,000 As a leading provider of domain names and Internet-related services, our client has registered ...

Business Analyst, Niche and Unique Software Co. Banking

Performing detailed analysis of new functional requirements with clients and internal domain experts - Documenting functional requirements and ...

Fix Protocol Consultant - Investment Bank

Our Client is indeed one of the big names in the global invetment banking world. They are looking to recruit a professional with at least 3 to 5 year ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: