|
||
![]() |
||
![]() |
You position :Firefox >> Details | Please remember website domain names www.firefox-uk.cn |
|
|||||
| Mozilla Relieves Firefox, Explorer Security Headache | |||||
|
Mozilla , maker of open source Web browser application Firefox, released a new version of the program that fixes a security issue stemming from an interaction between Microsoft's (Nasdaq: MSFT) Internet Explorer (IE) and Firefox. Version 2.0.0.5 of Firefox was made available for download on Wednesday. The problem -- first reported by security firm Secunia -- arises on computers that have both IE and Firefox installed. When a user browses Web sites using IE, malicious code can be sent to Firefox and, notably, other programs on the user's computer. Mozilla, in its security blog, called on Microsoft to patch the hole on the IE side. For its part, though, Mozilla states that "[t]his patch for Firefox prevents Firefox from accepting bad data from Internet Explorer."
Mozilla has taken pains to point out that the problem cannot occur when using Firefox to browse the Web and that it is not aware of attackers taking advantage of the vulnerability. It also notes in its security blog that "[a] similar interaction between Safari and Firefox was reported earlier and fixed by Apple." The blog entry announcing the fix and calling on Microsoft to repair the problem from its side was authored by Window Snyder, chief security officer for Mozilla. It is the only comment that Mozilla is making publicly about the matter, Mozilla spokesperson Steve Naventi told LinuxInsider. Not Just Firefox The issue has indeed been fixed from the Firefox side, but a hole remains open from the IE point of view, Danish programmer and self-described hacker Thor Larholm noted in a Wednesday blog entry. "I can still automatically launch a wide range of external applications from Internet Explorer and provide them with arbitrary command line arguments. AcroRd32.exe (Adobe Acrobat PDF Reader), aim.exe (AOL Instant Messenger), Outlook.exe, msimn.exe (Outlook Express), netmeeting.exe, HelpCtr.exe (Windows Help Center), mirc.exe, Skype.exe, wab.exe (Windows Address Book) and wmplayer.exe (Windows Media Player) -- just to name a few," he said. Finger-Pointing Game The fault, though, lies with both, according to Chenxi Wang, principal analyst with Forrester Research. "This is really a gray area," she told LinuxInsider. Microsoft should be vigilant about what IE passes on to other programs, she asserted. On the other hand, all programs -- Firefox included -- are responsible to protect themselves against potentially malicious input. "This issue does highlight the importance of investigating your trust model and your assumptions," Wang said. "I bet the Firefox designers did not envision such an attack when they decided to allow arbitrary parameters to be passed from IE, or any other Windows application. Many security attacks happen because of misplaced assumptions, and this is one of them." |
|||||
| firefox录入:renwen@renwen.net 责任编辑:renwen@renwen.net | |||||
| 【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口】 | |||||
Netizen : (only shows the latest 10. Comment on the contents represent users view, and has nothing to judge! ) |
| | As the front page | hosting | Domain Name Registration | |
|
|