BetaONE will rise again!


Reply
  #1  
Old 7th Jan 05, 02:30 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 30,940
NewsBot will become famous soon enough
Mozilla Software Vulnerabilities Revealed
Mozilla Foundation browser users have been warned to be on the look-out for two new flaws in their browsers. SecurityFocus has released a security warning covering a series of problems affecting the browsers on a variety of platforms.

The first could allow the source of downloads to be spoofed. It affects the latest versions of both Firefox and Mozilla and is explained in detail on Bugzilla. The problem relates to the way the downloads dialog box displays long filenames - by default, sticking in some unusual characters can prevent part of a download URL from being displayed. This could make a file appear to be coming from a genuine source when it's actually on a completely different server. Users are warned to not follow links from untrusted sources.

Users face a second problem connected to the way the browsers handle news:// links to newsgroups. Hackers could create malicious links to news servers which cause a buffer overflow, allowing them to inject hostile code into systems. It's understood to affect versions of Mozilla before 1.7.5; Firefox users were also warned to ensure they were running v1.0 to minimise the risks.

Finally, a third problem affects the Firefox/Thunderbird combination. It's said to be a bit less serious than the first two, but involves temporary files being stored in a way which means anyone could look at files people have been downloading on the same machine.

View: Secunia dialog box warning | Mozilla NNTP flaw details | Temporary files problem

News source: Neowin
Full story: View Here
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Software Should Not Be Copyrighted -- Lawsuit NewsBot NeoWin News 0 14th Dec 04 06:30 PM
Mozilla Celebrates 10 Million Firefox Downloads NewsBot NeoWin News 0 12th Dec 04 12:30 AM
Chinese Goverment to Limit Foreign Software Use NewsBot NeoWin News 0 27th Nov 04 07:00 AM
Microsoft Sharpens Its Software Factory Vision NewsBot NeoWin News 0 27th Oct 04 05:30 PM
E-Voting Cos. Reveal Software to Feds NewsBot NeoWin News 0 27th Oct 04 04:30 PM


All times are GMT +1. The time now is 09:31 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.