Security Flaw In Firefox 3 Leaves Browser Open To Attack


By Stefanie Hoffman, ChannelWeb

6:13 PM EDT Wed. Jun. 18, 2008
Mozilla Firefox 3.0 may be new but it might not be secure. Just five hours after Mozilla's release of the updated Web browser Tuesday, researchers at TippingPoint detected a critical security vulnerability in Firefox 3.0, allowing remote attackers to take control of a user's PC.

In addition to Firefox 3.0, the security flaw also affects previous versions of Firefox 2.0x.

As with most zero-day vulnerabilities, remote attackers could execute malicious code on a user's computer if they successfully exploited the flaw, according to a TippingPoint blog post. Consequently, TippingPoint researchers designated the error with a "high" severity rating.

However, like most browser-based vulnerabilities, a successful attack would also require active user participation. An attacker would have to entice a user to click on a malicious link sent in a phishing e-mail or to visit a malicious Website for the user's computer to become infected.

According to the company's Zero-Day Initiative Website, TippingPoint has already contacted Mozilla regarding the issue and a fix is currently in the works. However, the exact patch release date remains to be determined.

Once the vulnerability is repaired, TippingPoint said it planned to publish the security advisory on the "Published Advisory" page on its Website.

"Working with Mozilla on past security issues, we've found them to have a good track record and expect a reasonable turnaround on this issue as well," said TippingPoint.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
Save up to 15% on software from Acronis, Veeam, AVG, VMware, etc
Sublime Solution, Valued Added Reseller specializing in virtualization solutions, is offering an aggressive discount (up to 1...
Partners Rock!
Endian introducing its new Partner's Rock! program to the U.S.
RELATED BLOG >>
Photo
Apple is working double time to create a security patch for a critical SMS flaw that opens users up for attack when they sends text messages via the iPhone.
ADVERTISEMENT




CHANNEL SERVICES >>

techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Real Time Software Engineer 5
Boeing seeking Real Time Software Engineer 5 in Anaheim, CA
spacer