|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Flaw found in Firefox By Dawn Kawamoto, CNET News.com April 06, 2005 URL: http://www.zdnet.com.au/news/security/soa/Flaw-found-in-Firefox/0,130061744,139187286,00.htm
A flaw has been discovered in the popular open-source browser Firefox that potentially could release sensitive information stored in memory, according to a report by security information company Secunia. While the flaw is only rated as "moderately critical," the rapid adoption of the open-source browser may put a growing number of users at risk. Prior to the release of version 1.0, downloads of earlier versions of the browser had reached 8 million within the first 18 months. Firefox versions 1.0.1 and 1.0.2 contain the flaw, Secunia said. The vulnerability stems from an error in the JavaScript engine, according to Secunia. This error can expose arbitrary amounts of heap memory after the end of a JavaScript string. As a result, an exploit may disclose sensitive information in the memory. "Unlike other browser flaws, this one is not subject to phishing or access to the system. But it can expose sensitive information from other Web sites you visited and the information you entered there," said Thomas Kristensen, Secunia's chief technology officer. Mozilla is currently working on a patch, and no known cases have been reported, said a Mozilla spokesman. Secunia has developed a test that allows users to gauge whether their systems are affected by the vulnerability.
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |