Firefox Flaw Found and Fixed (Get the Patch)   - 1,522 Views,

Summary: A Firefox flaw which allowed for remote code execution was publicly disclosed yesterday. Today Mozilla, who distributes the Firefox software, released a patch for the Firefox flaw.

Previous Article « Free Wifi on City Buses - Public Transit Provides Public Transmit
Read Next Article » Video Headstone - Vidstone’s Serenity Panel Celebrates Life, After Death

  Follow Anne on Twitter     Friend Anne on Facebook

A critical security flaw in Firefox was disclosed yesterday, and patched today. Now that’s what I call quick service.

The flaw in Firefox was a buffer overflow flaw which allowed remote code execution, if exploited, meaning that people could access your system remotely, and run programs and do other nasty things on your computer, all from afar, and without your knowledge.

The flaw was discovered by independent security researcher Tom Ferris, who reported the flaw to Mozilla. However, according to a CNet report, Ferris “decided to publicly disclose the flaw after a run-in with Mozilla staff.”

“We’d like to make sure that by the time something goes public, we have a solution for the users,” said Mike Schroepfer, a director of engineering at Mozilla, yesterday, explaining that “We believe there is a buffer overflow issue. We are still determining whether it is exploitable by attack.”

Today they released a patch for the flaw, along with the following explanation:

“On September 6 a security vulnerability affecting all versions of Mozilla Firefox and the Mozilla Suite was reported to Mozilla by Tom Ferris and on September 8th was publicly disclosed.

On September 9, the Mozilla team released a configuration change which, as a temporary measure to work around this problem, disables IDN in the browser. IDN functionality will be restored in a future product update. The fix is either a manual configuration change or a small download which will make this configuration change for the user. ”

So there you have it. You can get the manual fix, or the patch, for the Firefox flaw here.

Firefox Flaw Found and Fixed (Get the Patch)

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « Free Wifi on City Buses - Public Transit Provides Public Transmit
Read Next Article » Video Headstone - Vidstone’s Serenity Panel Celebrates Life, After Death

Read more:

»  Firefox “Lambda Replace Heap Memory” Security Flaw Reveals Sensitive User Information

»  New Critical Internet Explorer (IE) Flaw Involves Msdds.dll

»  Windows ActiveX Flaw Still Active After Patch

»  Apple Releases New Batch of Patches, Fixes International Domain Names Phishing Flaw in Safari

For additional similar stories check out our archives on Apple & Mac, Security, Windows

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 9/10/2005
The Internet Patrol
Patrolling the Internet for You!