BetaONE will rise again!


Reply
  #1  
Old 5th Sep 07, 12:39 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,559
NewsBot will become famous soon enough
Firefox Vulnerable to Protocol-Handling Bug Attacks
Firefox remains vulnerable to attacks exploiting protocol-handling bugs, even though it was patched twice in July, a pair of security researchers said this weekend. Billy Rios and Nate McFeters, who spelled out design and functionality vulnerabilities in Windows' Uniform Resource Identifier (URI) protocol handling as recently as mid-August, said Saturday that they have uncovered another way hackers could send malicious code to users via browsers.

"Once again, these URI payloads can be passed by the mailto, nntp, news, and snews URIs, allowing us to pass the payload without any user interaction," claimed Rios in a posting to his blog. "Although the conditions which allowed for remote command execution in Firefox 2.0.0.5 have been addressed with a security patch, the underlying file type handling issues which are truly the heart of the issue have NOT been addressed," he added.

View: The full story
News source: PCWorld

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Internet Explorer 7 Beta 3 memory handling advantages over Firefox NewsBot ieXbeta News 1 22nd Jul 06 12:25 AM
Internet Explorer 7 Beta 3 memory handling advantages over Firefox NewsBot ieXbeta News 0 1st Jul 06 06:30 AM
Neowin Member Interview: Asa Dotzler - Firefox Developer NewsBot NeoWin News 0 20th Jul 05 09:30 PM
Firefox breaks 25 million downloads in less than 100 days NewsBot NeoWin News 0 18th Feb 05 07:30 AM
Firefox: The Road Ahead NewsBot NeoWin News 0 15th Jan 05 02:00 AM


All times are GMT +1. The time now is 02:44 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.