You are here: silicon.com > Software > Security Strategy

Security Strategy

Firefox update plugs cookie flaw

Thunderbird also patched...

Tags: mozilla, cookie, firefox, thunderbird

By Candace Lombardi

Published: 26 February 2007 09:05 GMT

Mozilla has released updates to its Firefox browser and Thunderbird email client for Mac, Linux and Windows users.

Mozilla said in a post on its development site: "Due to the security fixes, we strongly recommend that all Firefox users upgrade to these latest releases."

Mike Schroepfer, vice president of engineering at Mozilla, said in a statement: "This update resolves the location.hostname vulnerability and other security and stability issues."

The location.hostname vulnerability Schroepfer referred to was the Firefox cookie flaw discovered by Michal Zalewski, an "ethical hacker" from Poland.

In mid-February, Zalewski posted his proof-of-concept on a mailing list for other security experts. His note said a flaw in Firefox could allow hackers to set or change cookies for their own purposes. A fix for the high-impact flaw was made by Firefox developers in recent weeks.

This update includes the patch for that fix, as well as a fix for the critical level flaw involving memory corruption that can lead to crashes. That flaw left people using JavaScript in their mail - a practice Mozilla "strongly discourages" - open to attacks.

Schroepfer said: "Thanks to the work of our contributors we have been able to address these issues quickly in order to minimise the security risk to Firefox users."

The update is available in 37 languages from the GetFirefox.com and GetThunderbird.com websites for 1.5.0.10 versions of Firefox and Thunderbird, as well as Firefox 2.0.0.2. It is also available by clicking "Check for Updates... " in the Firefox Help menu.

Candace Lombardi writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...

Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?


  • Jobs
.Net Technical Lead - agency - London Bridge

Advaced experience in (x)html, css, javascript and ajax You MUST, Must have built and developed mulitple client facing websites. In order to be ...

Software Support Engineer (FIX)- Financial Software- LONDON 35k +

FIX Software Support Engineer required to join a leading financial traders based across the globe. You will support over 100 clients on the ...

Technical Support Analyst, FIX, Java, Unix Solaris, Windows, Trading,

Ideally you shall come from a trading background and have experience of trading software and the life-cycle, especially knowledge of FIX. Technical ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: