Slashdot Mirror


Security Issues in Mozilla

paulius_g writes "SecurityFocus has released a security warning with three problems that affect Mozilla on all platforms. The first issue allows the source of a download to be spoofed, generating a fake URL. This security issue is really easy to replicate: Create a long URL and the downloading box will only display its ending (Mozilla and Firefox). The second issue was created by the way that Mozilla's browsers handle news:// links to newsgroups, hackers can easily create false links and create a buffer overflow (Mozilla 1.7.5 and below, Firefox versions before 1.0). The third exploit affects machines with multiple users. The way that Firefox and Thunderbird store files allows every user to see them and to probably catch the other user's surfing habits (Firefox and Thunderbird). Let's hope that these will be fixed soon!"

6 of 454 comments (clear)

  1. It's fulfilling its prophecy by mOoZik · · Score: 1, Redundant

    As it becomes more and more popular, more and more bugs will be discovered. There is no inherently secure piece of software: it's only a matter of problems / volume.

  2. Re:Misleading Article by recursiv · · Score: 0, Redundant

    Go to http://secunia.com/advisories/13599 (linked in post) and it says: Solution Status: Unpatched

    Why is everyone saying these are fixed?

    --
    I used to bulls-eye womp-rats in my pants
  3. Re:Even then.... by IcEMaN252 · · Score: 0, Redundant

    I would never suggest anything of the sort. You must work for SCO or something to suggest that I was suggesting that.

    <Quasi-seriousness>
    IE does suck all on its own, but this is /. and serious reflection on situation is seldom the norm.
    </Quasi-seriousness>

    --
    CitrusTV (http://www.citrustv.net): the Nation's Oldest & Largest Entirely Student-Run Television Station
  4. Re:Even then.... by spac3manspiff · · Score: 0, Redundant

    IE is 25 MB Firefox is 4.7MB thats why ie also sucks

  5. Re:Unacceptable by generic-man · · Score: 0, Redundant
    --
    For more information, click here.
  6. Re:Even then.... by spac3manspiff · · Score: 0, Redundant

    well there is a 900K linux distro