Mozilla Patches New Firefox Flaw

By Nate Mook | Published September 12, 2005, 12:09 PM

Mozilla developers acted fast to patch a new security vulnerability in Firefox, which slipped its way into the first beta build of Firefox 1.5 and exists in earlier versions as well. However, the patch simply disables the buggy feature while a permenant fix is worked out.

The vulnerability relates to Firefox's handling of IDN, or international domain names, and can be exploited by long Web links that contain dashes. The flaw causes a buffer overflow and opens the door for malicious code to be run on a PC. No code to exploit the problem has surfaced, but Mozilla developers say they are taking it seriously.

Comments

View comments by with a score of at least

"Mozilla developers acted fast to patch a new security vulnerability in Firefox, which slipped its way into the first beta build of Firefox 1.5 and exists in earlier versions as well."

It exists in earlier versions so I would say that it has a little weight.

Score: 0

|

Since going corporate, Mozilla can't get anything right. Firefox has been trashed since 1.04. Sad.

Score: 0

|

Goind corporate has nothing to do with this. This flaw has been there since the begining. Number of flaws aside I look at how promptly these flaws are fixed hen they are discovered. So far Mozilla seems to be winning that race. Microsoft has this bad thing at time about waiting til the flaw is exploited before they fix it. While this is not a permanent fix at least Mozilla has done something about it.

Score: 0

|

They also tell you how to manually disable it. Iguess that for those of us using the beta because the patch is for 1.0.6

Score: 0

|

Again Mozilla fixes things while Microspud dawdles, IE the decision to cancel update tues.......

Score: 0

|

Again exploiters didn't abuse the flaw because MS is a bigger target.

Score: 0

|

Indeed, from what I have seen microsoft has a bad tendancy to wait until the flaw has been exploited before they do anything about em.

Score: 0

|

Yes, they issued a patch... and if you read the article fully, you'd understand that the patch is really just a configuration change that disables IDN functionality. It doesn't really *fix* anything.

Score: 0

|

MS patches most flaws promptly(within 2 months), but they leave a few extremely dangerous ones in there for years and years...just because.

Heck, they still haven't fixed one vulnerability back from Windows 3.1 that can render your computer dead unless you dual-boot with linux. I'm just waiting for Vista to be released so I can try it out(on my own computer) and see if they've finally gotten around to correcting it..

Score: 0

|

2 months isn't very prompt. Although this isn't a permanent fix, it's good that the Mozilla foundation isn't just turning their back on it. They are letting people know what they need to do until they can get a patch out, which I would be willing to bet will be available within a week.

Score: 0

|

bullcrap

Score: 0

|

Disabling functionality is a work-around... not a fix. You would be stating the same point if the table was reversed and this were an IE issue.

Score: 0

|

disabling a functionality simply because there will be a major update to the product that will fix the issue anyways IS a valid way to get around that bug and is STILL faster than MS who sometimes took 6 months and still ended up with simply removing a functionality.

To all you MS fanboys: FF is, compared to MSIE, a brand new product that already posesses more than twice the functionality of IE. Ofcurse there will be quite a few bugs/flaws found at first but thats just because we are all humans. The real difference is the fact that those bugs are discussed and fixed imidiately (48h-1week compared to ~2months)

Score: 0

|

As I previously stated, on other news items, there is definiately NO software that is 100% secure! Microsoft Internet Explorer has been the major target of most security attacks. Now that Firefox is gaining in popularity, we will see more and more vulnerabilities emerge.

We're only human!

Score: 0

|

Let me know of a vulnerability in calc.exe.

Score: 0

|

lol. You know what he/she means. In any complex program that has access to the Internet, there's going to be a vulnerability somewhere. Period.

Score: 0

|

Not a vulnerability, but a fun bug that existed for YEARS.

http://www.cnn.com/TECH/...uting/9811/05/count.idg/

Score: 0

|

HAHAHAHAHAHA

Oh man that's funny...

Score: 0

|

And we shall say that the door has slammed him right in the big red nose.

LOL

Score: 0

|

Not really--the bug mentioned wasn't a security vulnerability at all, and the Calculator in WinXP doesn't have that bug, because it has been fixed. So, no point was made.

Score: 0

|

Good job Mozilla. I think most people would rather put up with (mildly) reduced functionality than be exposed to malware.

I know I would.

And the permanent fix will be out soon I'm sure.

Score: 0

|

Agreed. In fact I think that in SOME cases MS may want to consider this. The problem with MS is that changes in IE can affect the rest of the OS. Take this case as an example. What if there is a company that uses the IDN functionality that the patch disables? This happens more so with MS features, so MS would get too much flak for disabling Remote Registry Service to prevent a security compromise, for example.

Score: 0

|

That's a good point. It's a tough decision either way for MS.

Score: 0

|

"The problem with MS is that changes in IE can affect the rest of the OS"

Well that's what they get for integrating the blasted thing so tightly into the OS. All they accomplished by integrating it is making it harder on themselves to fix flaws.

As far as them catching flak for disabling a feature, I don't see what it would hurt. From what I can sssssee they catch more flak than any other company in the industry, what's a little more gonna hurt

Score: 0

|

... As it says it also applys earlier versions ... so plz read the full article ...
But it is a couple of days since they came with a patch for 1.4 ..

Score: 0

|

Is this real news? Firefox 1.5 is still in beta, the beta phase is to discover present bugs and to wipe those away. No problems with the report though

Score: 0

|

It was actually discovered in previous versions of FF and Mozilla released the beta right before the announcement, so it has nothing to do with the beta. However Mozilla was quick to respond and has a temporary patch to help folks out for now, so I can't gripe about that.

Score: 0

|

As if people are going to notice the little red icon to go manually install the patch.

Score: 0

|

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.

Playing catch-up in 2010: Windows Mobile, BlackBerry, and Symbian

Microsoft, RIM, and Nokia are each working on improved mobile operating systems. But could these efforts add up to too little, too late?

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Report: Microsoft to randomize Europe's browser screen choices

The fact that "A" is for "Apple" was apparently at the heart of browser vendor objections to Microsoft's alternative to listing IE first.

Will Nokia's plans further alienate American consumers?

A look at Nokia's plans for the coming years does little to shine up the company's increasingly dull image.