Whole Network Most Recent TOP10 Interviews Reviews Security Tools

 

Mozilla Releases Two Bug Fixes For Firefox

Filed in archive Security by Eileen Peck on August 01, 2007

firefox-logo.jpg
Mozilla released a patch on Monday to its Firefox browser product that fixes two known issues: earlier releases of Firefox did not percent-encode spaces and double-quotes in uniform resource identifiers, which caused problems when Firefox handed off information to another program. The patch also resolves a bug which could have allowed privilege escalation attacks, by exploiting unsecure code in add-ons that generate "about:blank" windows. An attack could allow the about:blank windows to be populated, including the creation of about:blank windows and the use of JavaScript URLs in new windows.

Firefox 2.0.0.6 is available from the Mozilla Web site. Existing registered Mozilla users will be notified about the availability of the patch. Applying the patch will completely resolve both issues, but Mozilla also offered a workaround for the bugs, to ensure that the browser is secure. Mail related links will always prompt for confirmation before launching an external program via Firefox, if the following remedy is in place:

Enter about:config in the location bar
Enter "warn-external" in the Filter: box
Double-click to set the mailto, news, nntp, and snews lines to true


Advertisement


Permalink: Mozilla Releases Two Bug Fixes For Firefox
Tags: Mozilla  Firefox  security  patches  2007  mozilla+releases  fixes+firefox  releases+fixes 

Trackback: http://www.creative-weblogging.com/cgi-bin/mt-tb.pl/84161



Advertisement


Advertisement


CW ToolbarInstall
RSSrss   | See all blog subscribe options
Googlegoogle   |   What is RSS?
Yahoo!yahoo
AddthisAddThis Feed Button
BloglinesBloglines
Newsletter
Advertisement - Book yours here.

Use our search feature to look for other interesting posts

Just this blog Whole network
 
  • Would you like to see your text link here? Let us know!
Advertisement
Book yours here.

TierOneAds


Advertisement - Book yours here..
 
Tagcloud: General Humour Info Interviews Networking Products News Quickies Reviews Security Software Tools Tutorials Wireless