---
Email this article   Print article 

Mozilla Working On Fix For Firefox Flaw

By Sharon Gaudin, CRN
February 22, 2007    3:25 PM ET

Mozilla said it is still working on the next security update for Firefox and will release it as soon as work is completed on a fix for a flaw that lets hackers tamper with how Web sites are displayed.

The security update for the open-source browser originally was slated to be released on Feb. 21 but was pushed back in order to accommodate a fix for this new flaw " the location.hostname vulnerability -- and other security and stability issues.

Michal Zalewski, a Polish security researcher, was the first to disclose the vulnerability last week on his mailing list, Full Disclosure. He explains that the flaw is in the most recent version of the Firefox browser -- 2.0.0.1 -- but adds that it affects other recent versions, as well.

The vulnerability allows malicious Web sites to manipulate authentication cookies for third-party sites.

"The impact is quite severe: Malicious sites can manipulate authentication cookies for third-party webpages, and, by the virtue of bypassing same-origin policy, can possibly tamper with the way these sites are displayed or how they work," Zalewski writes.

Mike Schroepfer, vice president of engineering for Mozilla, says the new security update will be out "soon."

"We have not heard of any reported exploits of these vulnerabilities, however, we are working to address the issue as quickly as possible to minimize the security risk to Firefox users," he wrote in an email response to InformationWeek questions. "Mozilla takes security vulnerabilities very seriously. Our contributors have been working through the weekend to address this issue as quickly as possible."

Zalewski offers an online determination of whether your machine is at risk.

To continue reading this article, please download the CRN Tablet Edition app from the iPad App store.

SHARE THIS ARTICLE

More Security

Recent Articles

Bit9 Security Survey: Nobody Wants To Be A Headline

What's keeping IT security professionals awake at night? These survey results provide insight into perceived threats and vulnerabilities, the effectiveness of security practices, and opinions about disclosure practices.

Nix That Click: Six Scareware Scams To Watch Out For

SpywareRemove.com provides a list of some of the nastiest rogue antispyware programs out there -- designed to trick people into paying to remove malware from their computers.

Malicious Malware: Six Ways Cybercriminals Beat Security

Cybercriminals have become adept at going around the latest security defenses. Here's a list of some of the most innovative malware in use today.

  More Slide Shows




Related Videos
Loading...