• Main
  • Apple
  • Gamers
  • Software



Lost Password? | Register
NewXwin.net
Mozilla investigates critical Firefox 3.0 bug
Morshad Morshad published 19 Jun 2008, 20:29 in main - 441 views
Fav
ImageMozilla Corp. today downplayed a threat posed by the first vulnerability reported for Firefox 3.0, telling users that the risk is "minimal."

"There is no public exploit, the details are private, and so the risk to users is minimal," Window Snyder, Mozilla's chief security officer, said in an entry to a company blog.

According to the security company that reported the vulnerability to Mozilla, the bug is present in the Windows, Mac OS X and Linux versions of Firefox.

Snyder was responding to news yesterday that 3Com Corp.'s TippingPoint, a security vendor that runs the Zero Day Initiative bug bounty program, had purchased a critical Firefox 3.0 vulnerability from an unnamed researcher and then forwarded information on the bug to Mozilla.

As per its policy, TippingPoint said it would not release details of the bug until Mozilla has crafted a patch. Yesterday, however, it noted that the vulnerability would let hackers execute remote code -- making the bug a critical flaw -- and that it would require some action by the potential victim, such as clicking on a link in an e-mail message or visiting a malicious or compromised site.

Today, Terri Forslof, TippingPoint's manager of security response, expanded somewhat on the vulnerability's range. "It's not operating system specific," she said. "It's browser specific, only on Firefox, but on Windows, Mac and Linux."

Snyder confirmed that she had received word from TippingPoint -- Forslof said she e-mailed Snyder directly with a heads-up -- and that the Mozilla team was looking into the problem. "To protect our users, the details of the issue will remain closed until a patch is made available," she said.

Yesterday, TippingPoint sounded confident that Mozilla would quickly fix the flaw. "Working with Mozilla on past security issues, we've found them to have a good track record and expect a reasonable turnaround on this issue as well," TippingPoint noted in a blog posting of its own.

Mozilla didn't provide additional information or offer recommendations for users, but Forslof was willing to do so. "This is in the same line as lots of other browser vulnerabilities," she said, "so the advice is in the same line, too. Don't click on links in e-mail, make sure the operating system is up to date, and don't visit unsafe sites."

Forslof added that the researcher, who has chosen to remain anonymous, is someone TippingPoint has worked with before. "He's a regular contributor to our program," she said.

She wouldn't disclose more than that, but did say it wasn't unusual for researchers to suddenly reveal a vulnerability that they'd discovered some time before. "I can think of several examples," Forslof said. "It's highly likely that he [found the bug] in their last version [of Firefox] and was just waiting for them to release 3.0 to see if they'd fixed it there."

According to both TippingPoint and Mozilla, the vulnerability is in the older Firefox 2.0 series as well as the brand-new Firefox 3.0, which launched Tuesday.
Tags: Mozilla, Firefox 3.0, Mozilla Firefox
    • 1
    • 2
    • 3
    • 4
    • 5
    4.00 (2 Votes)
    popup tail
  • 37 Diggs
Prev Article: Sprint Ready to Launch Long-Promised WiMax Service Next Article: Can Bangladesh be Asia's next technology destination?
  • Web 2.0: Google Chrome To Support Add-Ons
  • Mozilla: Firefox is faster than Chrome
  • How will Google Chrome change the user experience on the web?
  • Show More Related Articles
  • 1 Comments
  • 2 Favs

Who Faved This?

  • ShaonShaon 
  • ShakilShakil 
Random Technology News
Fav
AT&T expands mobile music offering through Napster
Morshad by Morshad in Technology News - 10/23/07 · 0 favs
Fav
Windows Live Installer 12.0.1471.1025
Shaon by Shaon in Software News - 11/06/07 · 0 favs
Fav
Review: New Sony Cyber-shot W-series compacts
News Editor by News Editor in Technology News - 01/24/08 · 2 favs
Fav
Microsoft Windows SDK for Windows Vista
Morshad by Morshad in Software News - 11/09/06 · 0 favs
Fav
Microsoft sees 2007 China sales up over 20%
Shakil by Shakil in Technology News - 04/10/07 · 0 favs
Latest Technology News
Fav
Review: Google's Mobile App & Voice Search for iPhone
News Editor by News Editor in Technology News - 6 hours ago · 1 favs
Fav
Amazon launches OLPC 'Give 1 Get 1' laptop drive
Shaon by Shaon in Technology News - 11/17/08 · 1 favs
Fav
HP fine-tunes Opteron rack box for nonexistent servers
Morshad by Morshad in Technology News - 11/17/08 · 1 favs
Fav
Japan: PS3 and DSi sales slow
Shaon by Shaon in Gamers News - 11/17/08 · 1 favs
Fav
More dirt in Vista Capable case surfaces
Shakil by Shakil in Technology News - 11/17/08 · 1 favs
Popular Technology News
Fav
Google and Apple Fight For New Voice Search Engine
Shakil by Shakil in Technology News - 11/14/08 · 1 favs
Fav
Microsoft load a Social Network on Live.com
Morshad by Morshad in Technology News - 11/13/08 · 1 favs
Fav
More dirt in Vista Capable case surfaces
Shakil by Shakil in Technology News - 11/17/08 · 1 favs
Fav
HP fine-tunes Opteron rack box for nonexistent servers
Morshad by Morshad in Technology News - 11/17/08 · 1 favs
Fav
Amazon launches OLPC 'Give 1 Get 1' laptop drive
Shaon by Shaon in Technology News - 11/17/08 · 1 favs

Main Menu

News
Advanced Search
Subscribe to Newsletter

Advertisement

Subscribe to NewXwin.net

Add to Technorati Favorites

Join My Community at MyBloglog!

My BlogCatalog BlogRank

TwitterCounter for @Morshad



Featured Sites

Privacy Statement | Contact Us
Copyright © 2003 - 2008 NS Network Organization. All right reserved.
NSOrg.com | EZthemes | Projects | Technology News | Apple News | Gamers News | Software News | Softwares & Products Reviews | Photoshop Tutorials