Firefox “Lambda Replace Heap Memory” Security Flaw Reveals Sensitive User Information   4/6/2005 - 698 views, 1 Comment

Summary: A security flaw known as the "JavaScript Lambda Replace Heap Memory Disclosure Vulnerability" has been found in the popular Firefox web browser. Firefox is an open source web browser which is available for Windows, OS X, and Linux, and which has experienced ...

Previous Article « Aunty’s Readers Sound Off About the FCC Broadcast Flag
Read Next Article » Unexpected Online Greeting Cards May Carry Trojan Horses

A security flaw known as the “JavaScript Lambda Replace Heap Memory Disclosure Vulnerability” has been found in the popular Firefox web browser. Firefox is an open source web browser which is available for Windows, OS X, and Linux, and which has experienced significant adoption in the past 18 months.

The new security flaw, which compromises the user’s “heap memory”, was discovered and announced by security company Secunia. While not exploitable by phishers or hackers seeking to gain access to the user’s computer, it can expose sensitive information both received from and entered in at websites which the user has visited.

Explained Thomas Kristensen, CTO of Secunia, “Unlike other browser flaws, this one is not subject to phishing or access to the system. But it can expose sensitive information from other websites you visited and the information you entered there.”

The Mozilla Foundation, which created Firefox, is working on a patch. In the meantime, Secunia has created a test which users can use to determine whether their system is at risk for exposure through the flaw. If so, Secunia recommends disabling JavaScript support on the user’s system until the Mozilla Foundation releases a patch.

Previous Article « Aunty’s Readers Sound Off About the FCC Broadcast Flag
Read Next Article » Unexpected Online Greeting Cards May Carry Trojan Horses

Get a FREE summary of the week's articles every Friday!
(You can stop it any time!)
    *We never share your email address with anyone

Email Address:
Date of first visit:
How you found us:

Be sure to watch for the confirmation email!

Subscribe
to The Internet Patrol on your cell phone    Email the link for this page to a friend!

Read more:

»  Firefox Flaw Found and Fixed (Get the Patch)

»  Firefox and Mozilla Still at Risk for Spoofing “Frame Injection” Security Flaw

»  FireFox Security Holes Lead to Warning

»  New Security Update for Firefox Fixes High Risk Issues

For additional similar stories check out our archives on Security

 

1 Comment »

  1. Thanks

    Comment by Lyle — 4/7/2005 @ 7:35 am

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
The Internet Patrol
Patrolling the Internet for You!