Slashdot Mirror


Unpatched Firefox Flaw May Expose Users

Corrado writes "CNET is reporting on a new Firefox flaw." From the article: "The problem lies in the way Firefox handles Web links that are overly long and contain dashes, security researcher Tom Ferris said in an interview via instant messaging late Thursday. He posted an advisory and a proof of concept to the Full Disclosure security mailing list and to his Security Protocols Web site...The public bug disclosure comes just as Mozilla released the first beta of Firefox 1.5. The final release of the next Firefox update, which includes security enhancements, is due by year's end, according to the Firefox road map."

5 of 390 comments (clear)

  1. AGAIN?!?!?!? by Anonymous Coward · · Score: -1, Troll

    Buffer overflow - AGAIN??

    Vulnerability disclosure immediately after new version release - AGAIN???

    WTF is up with Firefox? It's getting to be as bad as Internet Explorer!

  2. Re:It should be noted by B3ryllium · · Score: -1, Troll

    So you admit that there's a crack in the levee, but you want to see a gushing torrent of water before you'll admit that there's a problem?

    Zealot much?

  3. Re:Oh Crap! by Anonymous Coward · · Score: -1, Troll

    Why are you stealing? That is the Microsoftie way? If you are a Linux user, then you should have better ethics than that. Next you will be telling us that you voted for bush, all but assuring us that you are a true Microsoftie.

  4. Simple solution by Anonymous Coward · · Score: -1, Troll

    Just blame it on MS and keep quiet (or say "Firefox is great" and keep quiet)...

  5. Re:Oh Crap! by Anonymous Coward · · Score: -1, Troll

    Yeah, becuase if you're a Linux user, you're already resigned yourself to not running Windows commercial software that blows much of the OSS stuff out of the water (i.e. Photoshop).

    I guess you could run WINE though.