Welcome Guest. | Log In| Register | Membership Benefits
April 04, 2005 (1:26 PM EDT)

Firefox, Mozilla Bug Exposes Data

By TechWeb Technology News

Both Firefox and the Mozilla browser suite are vulnerable to attacks through flawed JavaScript engines, a security firm reported Monday.

The Mozilla Foundation's open-source browsers can be exploited by hackers to gain access to data currently in memory (but not information only stored on the hard drive), said the Danish security company Secunia.

According to Mozilla, use of a JavaScript "lambda" replace can expose arbitrary amounts of heap memory after the end of a JavaScript string. "Successful exploitation may disclose sensitive information in memory," said Secunia in its online alert.

The bug has been confirmed in the most recent versions of Firefox (1.0.2) and Mozilla (1.7.6), and at the moment, no patch is available. (Developers are working on one, however; to track what they're up to, check out this page on Bugzilla.)

Secunia recommends that users temporarily disable JavaScript support for what it considers a "moderately critical" bug.

Firefox and Mozilla users can try this test that Secunia has created to confirm that their browser is vulnerable.


CAREER CENTER
Ready to take that job and shove it?
SEARCH
Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.

Advertisement


TechSearch for related stories



Specialty Resources

Featured Microsite


Microsites

Featured Topic

Additional Topics

Crush The Competition

TechWeb's FREE e-mail newsletters deliver the news you need to come out on top.

Techencyclopedia

Get definitions for more than 20,000 IT terms.

Techwebcasts

Editorial and vendor perspectives


Vendor Resources


Focal Points