New York Web Design News September 9 2005, the latest breaking New York Web design news brought to you by,
Web Designs Now,Website Designs Now,New York Web Design Homepage,Web Design Services for New York, Connecticut, Long Island,New York Web Design Client Testimonials,Website Portfolio of New York Web Design, About this New York Web Design Firm,Contact this New York Web Design Firm

New Firefox Web Browser Risk
Web Design & Technology News, September 9, 2005

Google's Web Search Index Size
New UltraSparc 4+ Web Servers
Cisco / Macromedia Web Conferencing
Mozilla Web Browsers Vulnerable
Web Update: Oracle Acquires Siebel
Google Searches Web Blogs
New Firefox Web Browser Risk
Countries Urge Open-tech Standards

Security Patch for Windows
Microsoft Unveils New Brand
Sun's Java Web Integration Suite
Sony Adds Web Browser to PSP
Microsoft Web Plan Targets Google
Maxtor File Sharing and Backup
News Corp Acquires IGN

More Web Design News:
2007 Current News
2007 May
2007 March
2006 November
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 September
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 February
2004 March
2004 February
2004 January
2003 December
2003 November
2003 October
2003 September
2003 August
2003 July
2003 June
2003 March - May



September 9, 2005

A new, unpatched flaw affecting all versions of Firefox Web browsers could let attackers run code on users' PCs, a security researcher has warned.
By Joris Evers

A new, unpatched flaw affecting all versions of Firefox Web browsers could let attackers run code on users' PCs, a security researcher has warned.

The problem lies in the way Firefox handles Web links that are overly long and contain dashes, security researcher Tom Ferris said in an interview via instant messaging late Thursday.

He posted an advisory and a proof of concept to the Full Disclosure security mailing list and to his Security Protocols Web site.

The security vulnerability is a buffer overflow flaw that "allows for an attacker to remotely execute arbitrary code" on a vulnerable PC, Ferris said. An attacker could host a Web site containing the malicious code to exploit the flaw, he said. Though his proof of concept only crashes Firefox, Ferris claims he has been able to tweak it to run code.

Buffer overflows are a commonly exploited security problem. They occur when a program allows data to be written beyond the allocated end of a buffer in memory. A computer can be made to execute potentially malicious code by feeding in extra data that is designed to flood the buffer.

Ferris reported the bug to the Mozilla Foundation on Sunday, intending to go through the organization's bug-reporting process, he said. However, in an example of the uneasy alliance between security researchers and software makers, he decided to publicly disclose the flaw after a run-in with Mozilla staff, he said.

Mozilla, which coordinates development of Firefox and distributes the software, could not immediately comment on the flaw disclosure. However, a source close to the organization confirmed that Ferris had filed several bug reports, including this specific one.

Since the debut of Firefox 1.0 in November, usage of the open-source browser has grown. Security has been a main selling point for the Firefox Web browser over Microsoft's (MSFT) Internet Explorer Web browser, which has begun to see its market share dip slightly -- for the first time in years.

However, Firefox has had its own security woes. Several serious holes in the browser have been plugged since its official release, and experts have said that safe Web browsers don't exist.

The public bug disclosure comes just as Mozilla released the first beta of Firefox 1.5. The final release of the next Firefox update, which includes security enhancements, is due by year's end, according to the Firefox road map.

Ferris has found bugs in MSFT software before, including a yet-unpatched flaw in Internet Explorer that MSFT still has under investigation.

Earlier this month MSFT credited Ferris with reporting a bug in a Windows feature called Remote Desktop Protocol that could allow an attacker to remotely restart Windows systems.

Web Designs Now
Back to the Top


 © Copyright 2007, All rights reserved  |  Privacy Web Design Forums  |  Web Design News  |  Advertise  |  About Us  |  Contact Us  |  W3C HTML 
 Related Websites: New-York-WebDesign.com