New York Web Design News May 10 2005, the latest breaking New York Web design news brought to you by,
Web Designs Now,Website Designs Now,New York Web Design Homepage,Web Design Services for New York, Connecticut, Long Island,New York Web Design Client Testimonials,Website Portfolio of New York Web Design, About this New York Web Design Firm,Contact this New York Web Design Firm

Two Firefox Security Exploits
Web Design & Technology News, May 10, 2005

Netscape 8 Fights Phishing
Google Sells RSS Feeds
IE 7 Adds Tabbed Browsing
Firefox Growth Slows
Yahoo Hires Amazon Design Guru
Two Firefox Security Exploits
Apple Tiger OS Exploit
A Second Look at Social Networks
AskJeeves Growth Under IAC

Google Experiences Web Outage
New Photoshop CS2
Google Tool Speeds Web Surfing
Web Security Threats Branch Out
Online Shoppers Take 19 Hours
Rapid Revenue Growth of Net Ads
Macromedia Updates Web Conferencing
Net Ad Sellers Think Local

More Web Design News:
2008 Current News
2008 June
2007 June
2007 May
2007 March
2006 November
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 September
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 February
2004 March
2004 February
2004 January
2003 December
2003 November
2003 October
2003 September
2003 August
2003 July
2003 June
2003 March - May



May 10, 2005

Two vulnerabilities in the popular Firefox browser have been rated "extremely critical" because exploit code is now available to take advantage of them.
By Dawn Kawamoto

The cross-site scripting and remote system access flaws were discovered in Firefox version 1.0.3, but other versions may also be affected, said security company Secunia, which issued the ratings Sunday.

The two vulnerabilities, when combined, can be exploited, but no known cases have yet emerged where an attacker took advantage of the public exploit code.

One flaw involves "IFRAME" JavaScript URLs, which are not properly protected from being executed in the context of another URL in the history list.

"If you visit a malicious Web site, it can steal cookie information from other Web sites you had previously visited," said Thomas Kristensen, Secunia's chief technology officer. The attacker could then use that information to engage in identity theft or gain access to other password-protected sites that the victim visited.

A second vulnerability exists in the IconURL parameter in InstallTrigger.install(). Information passed to this parameter is not properly verified before it's used, allowing an attacker to gain user privileges. This flaw could allow an attacker to gain and escalate user privileges on a system.

People who want new extensions or themes need to go to the Mozilla update service. These extensions and themes will need to be manually installed.

Since the vulnerabilities were discovered over the weekend, the Mozilla Foundation, which owns Firefox, has taken preventive measures.

Mozilla has changed its update Web service and advises people to temporarily disable JavaScript.

However, people who download and install the Mozilla software from third-party sites are still at risk, Kristensen said.

"The threat still exists but is less critical now," he noted. "People can go to third-party sites to install the software, but it's not going to happen on as wide a scale as it had with the Mozilla sites."

Web Designs Now
Back to the Top


 © Copyright 2007, All rights reserved  |  Privacy Web Design Forums  |  Web Design News  |  Advertise  |  About Us  |  Contact Us  |  W3C HTML 
 Related Websites: New-York-WebDesign.com