Slashdot Mirror


Security Issues in Mozilla

paulius_g writes "SecurityFocus has released a security warning with three problems that affect Mozilla on all platforms. The first issue allows the source of a download to be spoofed, generating a fake URL. This security issue is really easy to replicate: Create a long URL and the downloading box will only display its ending (Mozilla and Firefox). The second issue was created by the way that Mozilla's browsers handle news:// links to newsgroups, hackers can easily create false links and create a buffer overflow (Mozilla 1.7.5 and below, Firefox versions before 1.0). The third exploit affects machines with multiple users. The way that Firefox and Thunderbird store files allows every user to see them and to probably catch the other user's surfing habits (Firefox and Thunderbird). Let's hope that these will be fixed soon!"

16 of 454 comments (clear)

  1. Only THREE? by w1r3sp33d · · Score: 3, Funny

    I guess they are not drinking the water from Redmond!

  2. Security by Anonymous Coward · · Score: 5, Funny

    Oh no! Time to switch back to IE.

    1. Re:Security by Anonymous Coward · · Score: 1, Funny

      Yes it is true... as the CIO of a Fortune 500 company I believe that this truly shows the shortcomings of open source and as such I have completely scrapped our 5 year open source migration project. Consequentially we will be permanently renewing our Select licensing agreement with Microsoft, and I hope that they will be gentle in the negotiations.

  3. Not Mozilla!! by 53cur!ty · · Score: 5, Funny

    The tragedy, the inhumanity!!

    Bet Gates is grinning today hoping everyone will forget his laptop crash.

    Don't Tech all day and night, visit:
    WillingtonKarateClub.org Training Tips and more

  4. 3 Whole Security Issues! Thank God... by codesurfer · · Score: 5, Funny

    that I can still wipe my Linux box, buy a copy of XP, install, activate, update, reboot, update, reboot, get SP1 & 2, reboot, update, reboot and I'll be able to use Internet Explorer, a safe alternative to....oh wait...

  5. Re:I bet they will be fixed within 24hours! by Anonymous Coward · · Score: 1, Funny

    "quote me! :)"
    -- xutopia

  6. Jeebus Kriced by killmenow · · Score: 5, Funny
    So sayeth the submitter:
    Let's hope that these will be fixed soon!
    Slashdot has gotten so bad, now the submitters don't even RTFA!
  7. Re:Umm.... by fitten · · Score: 5, Funny

    You mean I gotta walk all the way down to the systemroom to get my information? Crap, no wonder I haven't been able to find it in my office lately...

  8. Re:Even then.... by Anonymous Coward · · Score: 1, Funny

    Could you tell me where you have downloaded your version of IE for FreeBSD, Linux, OpenBSD and NetBSD ?

    These flaws are a real problem but Firefox, YES, is still better than IE. Besides, the first flaw is not a flaw: you must ALWAYS download stuff from people you trust (and even then , you have to check the sources with a GnuPG key ring).

  9. Re:Even then.... by Zate · · Score: 1, Funny

    *claps* He gets it ! YaY !!

    --
    IT is Dead. The industry is Shot Join Others Who Feel Your Pain http://www.internalstrife.com/
  10. Re:Even then.... by Squatchman · · Score: 1, Funny

    Thou shalt not defame the Holy Mozilla's name !!!

  11. Re:A fix? by Anonymous Coward · · Score: 3, Funny

    I'm tired of all these upgrades every once in a while.. Now, I'm using telnet to port 80 to read slashdot. It took me 4 hours to post this though..

  12. Long URL? by discordja · · Score: 3, Funny
    This security issue is really easy to replicate: Create a long URL and the downloading box will only display its ending (Mozilla and Firefox).

    is this long enough?
    http://hugeurl.com/?MjYzODBkMDE2ZTI1M2Q3ODQ5ZThlYm Q1YjRhMjMxMjgmMTImVm0wd2QyUXlVWGxXYTJoV1YwZG9WVll3 Wkc5alJsWjBUVlpPV0Zac2JETlhhMUpUVmpGYWMySkVUbGhoTW sweFZqQmFTMk15U2tWVWJHaG9UVmhDVVZadGVGWmxSbGw1Vkd0 c2FsSnRhRzlVVjNOM1pVWmFkR05GZEZSTlZUVkpWbTEwYTFkSF NrZGpTRUpYVFVad1NGUlVSbUZqVmtaMFVteFNUbUY2UlRGV1ZF b3dWakZhV0ZOcmJGSmlSMmhZV1d4b2IwMHhXbGRYYlVaclVsUk dXbGt3WkRSVk1rcElaSHBHVjJFeVVYZFpWRVpyVTBaT2NscEhj RlJTVlhCWlZrWldhMVV5VW5OalJtUllZbFZhY1ZscldtRmxWbV J5VjI1a1YwMUVSa1pWYkZKRFZqQXhkVlZ1V2xaaGExcFlXa1Zh VDJOdFNrZFRiV3hYVWpOb1dGWnRNSGRsUjBsNFUydGthVk5GV2 xSWmJHaFRWMVpXY1ZKcmRGUldiRm93V2xWb2ExWXdNVVZTYTFw WFlrZG9jbFpxU2tabFZsWlpXa1prYUdFeGNGaFhiRnBoVkRKT2 RGSnJhR2hTYXpWeldXeG9iMWRHV25STlNHaFBVbTE0VjFSVmFH OVhSMHBJVld4c1dtSkhhRlJXTUZwVFZqRmtkRkp0ZUZkaWEwcE lWbXBKZUUxR1dsaFRhMlJxVWtWYVYxWnFUbTlsYkZweFUydGth bUpWVmpaWlZWcHJZVWRGZUdOSGFGaGlSbkJvVmtSS1QyUkdTbk poUjJoVFlrVndWVlp0ZUc5Uk1XUlhWMWhvV0dKWVVrOVZha1pI VGxaYVdFNVZPVmhTTUhCNVZHeGFjMWR0U2toaFJsSlhUVlp3V0 ZreFdrdGtSa3B6Vld4a2FXRXdjRWxXYlhCTFpXczFWMWRzYUZS aE1sSndWV3RhUzFZeFVsaE9WemxzWWtad2VGVXlkR0ZpUmxwel UyeHdXbFpXY0hKV2FrWkxWMVpHY2sxV1pGZE5NRXBKVm10U1Iy RXhXWGxVYTFwaFVqSm9WRlJYTlc5a2JGcEhWbTA1VWsxWFVucF dNV2h2VjBkS1JrNVdWbFZXYkhCWVZGUkdVMk15UmtaUFYyaHBV bGhDV1ZacVNqUlZNV1IwVTJ0a1dHSlhhRmhaVkVaM1pXeHJlV1 ZJWkZOV2ExcDVWREZrYzFVd01IbGhSbXhYWWxoQ1RGUnJaRVps Um1SellVWlNhVkp1UW5oV1YzaHJWVEZzVjJKR2FHcGxhMXB4V1 d0YWQyVkdWblJOVldSV1RXdHdWMWx1Y0V0V2JGbDZZVWRvV21F eVVrZGFWV1JQVWpKS1IxcEhiRmhTVlhCS1ZqRmFVMU14VVhsVV dHaGhVMFphVmxscldrdGpSbFp4VW10MFYxWnNjRWhXVjNSTFlU QXhSVkpzVGxaU2JFWXpWVVpGT1ZCUlBUMD0=
    --
    I stole this .sig
  13. Re:A fix? by vk2 · · Score: 3, Funny

    You could have reduced it to 2 hours if you had used both your hands to type.

    --
    No Sig for you.!
  14. Re:Yipee by dajak · · Score: 2, Funny

    Oh, a side note. If I have Windows and I want to use Mozilla, why do I have to use IE first to download mozilla?? I already have IE installed, why do I need to download yet another browser and install it?

    Never download Mozilla with IE or any other insecure product! Only download Mozilla with Mozilla!

    If you download it with IE you may not be downloading the REAL Mozilla. That's what I tell people who report Mozilla crashing and stuff like that. The real Mozilla is flawless. How do you know you are using the real Mozilla?

    Also never let someone else install Mozilla from a storage device. They may have tampered with it.

    Remember: It's an open source product, so anyone can recompile it with his own malware embedded!

    1. Is there a patch or do I have to download the whole browser and reinstall?

    See Tools>Options>Software Updates

  15. Re:Misleading Article by northcat · · Score: 4, Funny

    How can his post be rated informatve when it isn't true?

    You must be new here.