Image
Interordi Menu
Mega X.exe
Forum Ghost
Offline
6444 posts
Quote

The problem is caused by a buffer overflow in legacy Netscape code still included in the browser for animating GIF images, Chris Hofmann, director of engineering for Mozilla, said. Similar memory problems have affected Mozilla\'s browsers and Microsoft\'s Internet Explorer in the past. A malicious attacker could exploit them by creating carefully crafted image files that, when viewed by a victim in a browser, execute a program and compromise the system.

The flaw was discovered by Internet Security Systems, a network protection company, and patched before the public learned of the issue, Hofmann said.

\"We are staying ahead and being proactive in fixing the code,\" he said. \"The deciding factor, in this case, was the potential for this: It\'s a little easier for hackers to turn it into an exploit that could be dangerous.\"

The Mozilla Foundation released version 1.02 of Firefox on Wednesday to fix the problem and asked that all users to download and apply the patch.

Recently published data has prompted questions about the security of Firefox. Security technology provider Symantec said in this week\'s Internet Threat Report that during the second half of last year, 21 vulnerabilities affected Mozilla browsers and 13 flaws affected Internet Explorer.

However, only seven of the flaws in Firefox were considered \"highly severe,\" compared with nine in Internet Explorer.

Mozilla\'s Hofmann pointed to the data as a positive indication that the developers were doing a good job of securing the Firefox code.

\"As the data shows, the flaws are of lesser severity,\" he said. \"The kinds of things the Microsoft\'s browser is vulnerable to is much more worrisome.\"

On Tuesday, Mozilla president Mitchell Baker predicted that Firefox won\'t suffer nearly as many security flaws as Internet Explorer and that the increasing popularity of the open-source browser won\'t change that.

\"Microsoft has a proven track record with Internet Explorer,\" Microsoft said in statement. \"We continue to make significant investments in Internet Explorer, including Windows XP Service Pack 2, which features a much stronger security infrastructure to help thwart malware attacks, block suspicious content and eliminate many common spoofing attempts. In addition, Internet Explorer 7 will be a major upgrade that will focus on security.\"

Mozilla is currently reviewing the roughly 2 million lines of code that makes up the Firefox browser to find similar vulnerabilities to those patched Wednesday. Last August, the organization offered a bounty to anyone who finds significant flaws in the software. The developers are looking with particular intensity at the legacy code that remains in the browser.

\"Most of the things that we are looking at and fixing are potential exploits that no one has figured out how to exploit yet,\" Hofmann said.

Samsara
Superstar!
Offline
4039 posts
Quote

I updated a few minutes ago. Firefox 1.0.2


Shadowfire
The Third Commander
Inactive
653 posts
Quote

Quote:
Originally posted by Shithead and Fartboom
YOU ARE STUPID!!!!!!:cool:

Wow.. thank you for that scientifically proven, and highly insightful observation... I shall immediately take it to heart, you must be some kind of expert.. e_e
On Topic: I\'ve never really liked Firefox/MoZilla... I\'ve always used IE.. though I suppose I\'m even LESS safe with it


Image

Samsara
Superstar!
Offline
4039 posts
Quote

Yup, IE is very insecure. I like Firefox, now that I use it, I think it\'s one of the better browsers.


Unknown
Deleted account
Quote

Post redacted

Samsara
Superstar!
Offline
4039 posts
Quote

Yes. IE 7 should be coming out soon, but how old is IE 6? Quite old. How long has it been since Firefox last updated? Well, Firefox v1.0.2 came out on Wednesday, so that\'s two days. How old was Firefox 1.0.1, though? I\'d guess about a month.


SPT Layzner
The Blue Comet
Inactive
1472 posts
Quote

Quote:
Originally posted by Indifferent Protester
Yes. IE 7 should be coming out soon, but how old is IE 6? Quite old. How long has it been since Firefox last updated? Well, Firefox v1.0.2 came out on Wednesday, so that\'s two days. How old was Firefox 1.0.1, though? I\'d guess about a month.

Firefox 1.0.1 was released on Febuary 24th according to Mozilla\'s website...and I don\'t want to search the last time IE 6 got an update ;P


Image
Image

Samsara
Superstar!
Offline
4039 posts
Quote

Yeah. IE6 is about the same age as Windows XP, I believe and that is very old.


Black Dranzer.exe
World Traveler
Inactive
2827 posts
Quote

Quote:
Originally posted by Indifferent Protester
Yeah. IE6 is about the same age as Windows XP, I believe and that is very old.

Are you sure It though IE6 was a month later.


Hey beautiful people, you're better off trying to e-mail me than message me on here.

Samsara
Superstar!
Offline
4039 posts
Quote

It would make sence that IE6 would come out the same time as the OS that it was built into.