Malicious code in an image could enter PC through browser
Malicious code in an image could enter PC through browser
R E L A T E D   C O N T E N T
ADVERTISEMENT

Mozilla fixes new Firefox flaw

Users urged to download patched version immediately

Iain Thomson, vnunet.com 24 Mar 2005
ADVERTISEMENT

The Mozilla Foundation has released a new security patch for its Firefox internet browser and is urging users to install it.

The patch fixes a flaw in the software that handles animated GIF images that could cause a buffer overflow.

If a hacker embedded malicious code in an image it could conceivably enter a PC through the browser software, although no exploit code has yet been found in the wild.

"The Mozilla Foundation is deeply committed to providing its users with the safest internet experience possible," said Chris Hofmann, director of engineering at Mozilla.

"To deliver our users the experience they deserve, we must stay ahead of the curve in patching potential vulnerabilities. For example, the bug patched in this update has no known real world exploits, and we were able to provide a quick response."

The flaw came to light after work done by security researchers at Internet Security Systems but was fixed before they published their report. This is the second Firefox patch to be released in the past month. The buffer overflow patch is available here.

See also:

Users advised to diasable JavaScript in Firefox browserHoles could allow hackers to implant Trojan or key-logger  09 May 2005
'Use another product,' advises browser firm  28 Apr 2005
Incentives for users to identify flaws in Mozilla softwareUsers who find flaws offered $500 per bug plus a free T-shirt  31 Mar 2005
Global usage share nears nine per centIE5 users might be moving to Firefox not IE6, says web analytics firm  01 Mar 2005
Firefox market share gains slow to 15 per centStellar growth of open source browser begins to slow  28 Feb 2005
25 million downloads since NovemberOpen source browser making its way into the mainstream  22 Feb 2005

All Ecommerce

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities