Slashdot Mirror


Another Denial of Service Bug Found in Firefox 2

An anonymous reader writes "A second security flaw that could cause the new Firefox 2 browser to crash has been publicly disclosed. The vulnerability lies in the way the open-source browser handles JavaScript code. Viewing a rigged Web page will cause the browser to exit, a representative for Mozilla, the publisher of the software, said Wednesday. Contrary to claims on security mailing lists, the bug cannot be exploited to run arbitrary code on a PC running Firefox 2, the representative said. This flaw in the JavaScript Range object is different than the denial-of-service vulnerability in Firefox 2 that was confirmed by Mozilla last week. That bug is related to a more serious security hole, which was fixed in earlier versions of Firefox, the organization has said. The two 'crashers' are the only publicly released vulnerabilities that have been confirmed by Mozilla in the week since Firefox 2 was launched. The issues are only minor, the organization has said."

1 of 206 comments (clear)

  1. Re:LOL IE Users! by DeviousDevil · · Score: 0, Flamebait

    What a suprise slashdot/firefox fan boys don't mind the bugs in FF. If this was a bug being reported in IE you guys would be slagging both it and MS off even if you could simply turn script off, or wait for the patch. But because it's not IE (or an MS product for that matter) you don't bat an eyelid, further more you have a go at MS even though it's a FF problem, for crying-out-loud. You guys are such hypocrites. Oh and by the way MS release patches quite regularly (although they get slagged off for that as well, they can't win).