Firefox update postponed by newest bug
LATEST NEWS
- NZ game industry: Govt support for development increasing
- Telecom opens pre-orders for Samsung Galaxy S III || 4
- Video, connection costs major factors in broadband uptake: ComCom
- No more risk to privacy on Facebook, than web: MED
- Raspberry Pi arrives in New Zealand || 4
- InternetNZ invites ICT organisations to meet
SUBSCRIBE
Computerworld is New Zealand's only specialised information systems fortnightly. Subscribe now for $100 (23 issues) and save more than 37% off the cover price!
SIGN UP
The flaw could let a malicious site manipulate the authentication cookies for other sites' pages
By Gregg Keizer | Framingham | Thursday, 22 February, 2007
Mozilla will delay the next security update for Firefox so it can test a fix for a flaw that could be used by attackers by skirt security restrictions.
The flaw, disclosed on February 14 by Polish researcher Michal Zalewski on the Full Disclosure security mailing list, could let a malicious site manipulate the authentication cookies for other sites' pages. It is present in the most recent version of the open-source browser, 2.0.0.1.
According to Zalewski, the bug might allow hackers to "tamper with the way these [third-party] sites are displayed or how they work."
Mozilla developers jumped on the bug and produced a fix by the next day. However, adding the patch to the Firefox 2.0.0.2 and 1.5.0.10 updates, which are still under development, will require more work. "We had to respin for [the patch] and now have Firefox 2.0.0.2 rc4 and 1.5.0.10 rc2 builds," wrote Firefox developer Jay Patel on the Mozilla.dev.planning forum. "We are [now] shooting for a target ship date of Thursday 2/22."
Mozilla had earlier pegged Febuary 21 as its target release date.
The vulnerability was rated as "moderately critical" by Danish bug tracker Secunia. Symantec's DeepSight threat network rated it 7.1 out of a possible 10. For his part, Zalewski posted a demonstration of the flaw online.
On Monday, Zalewski made note of a new Firefox bug that could give cybercriminals a leg up when running phishing attacks. Firefox can be forced to spawn a window with blank address bar with the Reload button disabled, Zalewski said. "This can be used to evoke a false sense of security or authority in casual users," he wrote in his warning. Hackers would have to dupe users into visiting a malicious site to pull this off this kind of attack, however.
Mozilla, security vendors and even Zalewski ranked this more recent flaw as minor; Mozilla has not yet patched the problem, and it's unclear whether it will be fixed in the 1.5.0.10 and 2.0.0.2 updates.
Mozilla also said that the week's Firefox updates would include Windows Vista-related changes, including one that allows Vista users to update the browser without having to download and reinstall the entire browser.
MOST POPULAR
- Google search will incorporate 'knowledge graph'
- Chorus extends introductory fibre trial for RSPs until December
- IBM boosts returns to parent company, paying $20m to US
- Raspberry Pi arrives in New Zealand
- Wellington gears up for Digital Earth summit
- J*******k: Dirty word disappears from Apple iTunes store
Social Media @Computerworld NZ

Computerworld NZ has now reached LinkedIn! Join to expand your networks and meet others interested in information systems.






