Language Selection

English French German Italian Portuguese Spanish

Unpatched Firefox flaw may expose users

Filed under
Moz/FF
Security

A new, unpatched flaw in that affects all versions of Firefox could let attackers surreptitiously run malicious code on users' PCs, a security researcher has warned.

The problem lies in the way Firefox handles Web links that are overly long and contain dashes, security researcher Tom Ferris said in an interview via instant messaging late Thursday.

He posted an advisory and a proof of concept to the Full Disclosure security mailing list and to his Security Protocols Web site.

The security vulnerability is a buffer overflow flaw that "allows for an attacker to remotely execute arbitrary code" on a vulnerable PC, Ferris said. An attacker could host a Web site containing the malicious code to exploit the flaw, he said. Though his proof of concept only crashes Firefox, Ferris claims he has been able to tweak it to run code.

Severity:
Critical

Vendor:
Mozilla

Versions Affected:
Firefox Win32 1.0.6 and prior
Firefox Linux 1.0.6 and prior
Firefox 1.5 Beta 1 (Deer Park Alpha 2)

Full Story.

More in Tux Machines

Linux Desktop Evolution: Minor, Invisible, or Aesthetic

In the last two years, the Linux desktop has settled into a period of quiet diversity. The user revolts of 2008-2012 are safely in the past, and users are scattered among at least seven major desktops -- Cinnamon, GNOME, KDE,LXDE, MATE, Unity, and Xfce -- and likely to stay that way. So what comes next? What will the next innovations on the desktop be? Where will they come from? Prediction is as safe as investing in penny mining stocks, but some major trends for the next couple of years seem obvious without the bother of a tarot reading. Read more

Ubuntu Touch apps can run in windowed mode

The developers of the Ubuntu Linux operating system for desktop, notebook, and server computers are working on a touch-friendly version for smartphones and tablets, with the first Ubuntu phones expected to go on sale this year. Read more

Square tries to make open source “welcoming and inspiring” to women

What is open source? Simply put, it is source code (used to develop software programs) that is freely available and modifiable on the Internet. Open source developers from all over the world contribute to various projects, which are hosted on various websites—GitHub, a popular code hosting site, has over 8 million users and over 19 million code “repositories.” Read more

Citizens call on Dortmund to use free software

Four citizens of the German city of Dortmund have started a citizens’ initiative, asking the city council to seriously consider the use of free and open source software. “The city needs to recognise free software as a topic in the public interest”, the DO-FOSS initiators write. Read more