News
News
4/25/2006
01:53 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Firefox Bug Could Be Serious

A security firm fears that a zero-day vulnerability in a fully patched and most current version of Mozilla Corp.'s Firefox could be exploited.

A zero-day vulnerability in a fully-patched and most-current version of Mozilla Corp.'s Firefox could be exploited to crash the browser at the least, and at the worst, possibly introduce malicious code, a security company warned Tuesday.

The bug, which first appeared on Mozilla's Bugzilla listing a week ago on April 18, could be used by an attacker to crash Firefox by feeding it malformed JavaScript code.

Proof of concept code has been made public that crashes Firefox 1.5.0.2, the open-source browser's newest edition.

Although Danish vulnerability tracker Secunia ranked the threat as "low," its weakest warning, U.S.-based security vendor Symantec said the danger may be more dire.

"It does appear that triggering the vulnerability using the proof of concept results in the execution of data somewhere in anonymous memory, possibly in a portion of the heap," Symantec told customers of its DeepSight threat alert system Tuesday. "If this memory were somehow populated by an attacker with a malicious payload, this condition could likely be exploited to execute arbitrary code."

Firefox developers have come up with a patch -- one is listed in the Bugzilla report -- but has not been pushed out to users. Typically, Mozilla releases Firefox updates that include several security patches as it did recently when it rolled out version 1.5.0.2 with fixes for 24 bugs.

JavaScript-based vulnerabilities aren't new to Firefox -- nor to its rival, Internet Explorer. Several of the flaws fixed in the April 14 release of Firefox 1.5.0.2, for instance, were associated with JavaScript.

Internet Explorer's biggest threat of late -- the "createTextRange" vulnerability that was used by malicious Web sites to infect PCs with spyware and adware before Microsoft unveiled a patch on April 11 -- was also JavaScript-based.

Comment  | 
Print  | 
More Insights
The Agile Archive
The Agile Archive
When it comes to managing data, donít look at backup and archiving systems as burdens and cost centers. A well-designed archive can enhance data protection and restores, ease search and e-discovery efforts, and save money by intelligently moving data from expensive primary storage systems.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Elite 100 - 2014
Our InformationWeek Elite 100 issue -- our 26th ranking of technology innovators -- shines a spotlight on businesses that are succeeding because of their digital strategies. We take a close at look at the top five companies in this year's ranking and the eight winners of our Business Innovation awards, and offer 20 great ideas that you can use in your company. We also provide a ranked list of our Elite 100 innovators.
Video
Slideshows
Twitter Feed
Audio Interviews
Archived Audio Interviews
GE is a leader in combining connected devices and advanced analytics in pursuit of practical goals like less downtime, lower operating costs, and higher throughput. At GIO Power & Water, CIO Jim Fowler is part of the team exploring how to apply these techniques to some of the world's essential infrastructure, from power plants to water treatment systems. Join us, and bring your questions, as we talk about what's ahead.