Attack code out for old Firefox bug

If you haven't updated your Firefox or Mozilla Web browser lately, now might be a good time to do so.

Computer code that demonstrates how a known flaw in an older version of the browsers can be exploited in a potentially crippling attack was published on the Web over the weekend. The vulnerability was fixed in Firefox 1.0.5, released in July, and Mozilla Suite 1.7.9 according to Mozilla.

The code was published by Aviv Raff, a developer in Israel. "I think it's been enough time for people to upgrade from v1.0.4 of Firefox," he wrote on his blog on Sunday. Raff's code doesn't do much harm, but he notes that it would be easy to turn it into malicious code that commandeers a vulnerable system.

The vulnerability is in the way the Web browsers handle JavaScript, according to a Mozilla alert dated 12 July, the day Firefox 1.0.5 was released. An attacker could craft a malicious Web site use the flaw as a conduit to, unbeknownst to the user, run malicious code on a vulnerable PC.

Mozilla has released several updates to both Firefox and the Mozilla Suite since July. The latest version of Firefox is 1.5, which was released late last month. A security vulnerability that could cause the browser to appear to hang has already been pinpointed in that version, but Mozilla says it is a minor problem.

In other browser news, Microsoft on Tuesday released a patch that fixes four vulnerabilities in Internet Explorer. The software maker deems two of the flaws "critical," one is already being used to attack IE users, according to Microsoft.

Secunia is warning of a security flaw in version 8.01 of the Opera Web browsers and earlier versions may also be affected, the security monitoring company said in an alert on Tuesday. The flaw lies in the way the browser handles mouse clicks in new windows and in how it displays a dialog box for downloads, according to Secunia.

The Opera flaw could be exploited to trick users into downloading malicious programs, Secunia said. Users should upgrade to Opera 8.0.2 or later, which has been available since late July.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured