internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Opera
Internet Explorer 7
QuickTime for Windows
Winamp
Mozilla Firefox 3
Ad-Aware 2008 Free
Adobe Flash Player
Paint Shop Pro
Adobe Shockwave Player
AVG Anti-Virus Free
7-Zip

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Firefox Fixes IE Flaws
Firefox 2.0.0.5 Released with Nine Security Issues Fixed
Sean Michael Kerner

Mozilla has updated its flagship Mozilla Firefox browser to version 2.0.0.5 with at least nine security issues fixed.

Among them is one for an issue that was trigged when user also had Microsoft's Internet Explorer installed as well. Remote code execution by launching Firefox from Internet Explorer is addressed by Mozilla Security Advisory 2007-23.

The flaw was first reported on July 10. It involves the "firefoxurl://" uniform resource identifier (URI) handler, which enables Firefox to call on other Web resources.

Though Mozilla has fixed the flaw in Firefox 2.0.0.5, Mozilla's advisory noted that other Windows applications can be called in a similar way and also manipulated to execute malicious code.

"This fix only prevents Firefox and Thunderbird from accepting bad data," Mozilla stated in its advisory. "This patch does not fix the vulnerability in Internet Explorer."

Other critical bugs fixed include the following:

  • Mozilla Foundation Security Advisory 2007-18, which fixes crashes with evidence of memory corruption;
  • Mozilla Foundation Security Advisory 2007-23, which describes a Privilege escalation using an event handler attached to an element not in the document;
  • Mozilla Foundation Security Advisory 2007-19, which fixes a bug rated as High by Mozilla. It's a potential cross site scripting risk where scripts could be injected into another site's context by exploiting a timing issue.
  • Timing is also responsible for a low risk vulnerability addressed in Mozilla Foundation Security Advisory 2007-20 that could allow for Frame spoofing while a window is loading. According to Mozilla's advisory a pair of security researchers reported that it was possible to exploit a timing issue to inject content into about:blank frames in a page.

    "When opening a window from a script, it is possible to spoof the content of the newly opened window's frames within a short time frame, while the window is loading," the advisory states.

    The Firefox 2.0.05 release follows the 2.0.0.4 release by almost two months. Mozilla has not updated its Firefox 1.5.x series as part of this release update. Firefox 1.5.x was retired in May.

    News courtesy of internetnews.com

    July 18, 2007


    Download Mozilla Firefox 2!Download

    Download Microsoft Internet Explorer!Download

    View All Web Browsers

    Contents:
    1. Firefox 2.0.0.5 Released with Nine Security Issues Fixed


    Additional Articles:

  • Mozilla's Newest FireFox Takes Flight
  • Browser Wars v.2004: Part 1
  • Browser Wars v.2004: Part 2
  • Mozilla Firefox's Volunteer Launch Brigade
  • Rise of the Underdog Browser
  • Firefox Makes It Official
  • Add-ons Extend Firefox Growth
  • Getting the Most Out of Firefox
  • Firefox Thankful for Strong November
  • Firefox, Others at Phishing Risk
  • Browser Wars: Who's Winning, Who's Losing
  • Firefox Torches Competition for Enterprise Linux Award
  • Mozilla Updates Firefox
  • New Firefox Vulnerability Pushes Latest Update
  • Firefox Update Patches Three in Time
  • JavaScript Flaw Hits Mozilla Users
  • Firefox Popularity Spurs Mozilla Traffic Surge
  • Beware the Browser Backlash
  • Another Flaw Found in Mozilla
  • Google Extends Firefox
  • New Firefox Fixes Holes
  • Firefox Advocate Site Hit by Hackers
  • Mozilla Goes for More Green
  • IBM Donates Code to Firefox
  • Firefox Losing Its Grip?
  • Mozilla Under Fire
  • Mozilla FireFox DoS Exploit Code Released
  • Firefox: Nearly a Year Old And Now 100M Strong
  • Happy Birthday, Firefox 1.0
  • Firefox Upgrade Near
  • Firefox at Critical Mass?
  • New Firefox Kills Bugs
  • A Word-Wise Firefox Extension
  • Mozilla Plugs Firefox Bugs
  • FireFox Fixes by the Dozen
  • Goooaaal! Google, Mozilla Kick In Soccer Fix
  • Firefox 2.0: Mozilla's Tabs Overfloweth
  • Firefox 1.5.0.5 Fixes JavaScript Flaws
  • Firefox Is Doing So Well It's Now a Malware Target
  • Firefox 2.0 Beta Tweaking Its Look
  • The Firefox, IE Race to The Finish
  • Firefox Hits Seventh Heaven
  • Firefox 2.0 Release Candidate Goes Live Today
  • Double Deuce as Firefox 2.0 Nears Completion
  • Mozilla Fine-Tunes for Final Release of Firefox 2
  • Firefox 2.0 Released: 'Bon Echo' Lives!
  • Firefox 3.0 Already?
  • Path to Firefox 2.0 Is Cleared
  • Our Phishing Filter Is Better Than Yours!
  • Phishers Lurk for Firefox 2.0 Password Manager
  • Mozilla Fixes Firefox Flaws, Misses One
  • Mozilla Rakes In $53M
  • Mozilla Patches Some Firefox Holes
  • Mozilla Security: More Than Meets the 'Aye'
  • One Flaw and a First for Latest Firefox Update
  • Firefox 1.5 Gets Its Last Update
  • Firefox at Risk Because of Internet Explorer?
  • Mozilla Firefox Still at Risk
  • Will Mozilla's Fuzzer Break the Web?
  • Mozilla Updates Firefox Ahead of Black Hat
  • Flaw Still Shadows Firefox
  • Firefox Gets BitTorrent
  • Firefox Gets QuickTime Fix
  • Mozilla Separating Browser from the App
  • Firefox Fixes Cross-Site Flaws
  • Firefox Breaks Web Canvas
  • Warning on Spoofed Login Windows in Firefox
  • Mozilla Update Quashes Slew of Firefox Flaws
  • Firefox Update Tackles Pair of Critical Bugs
  • Will Design Flaws Flunk Firefox?




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers