2 Critical Flaws Found in Firefox
Posted: Tue May 10, 2005 10:30 am
Two new critical flaws were discovered in Mozilla's Firefox last Saturday and could allow websites to run malicious code when visited. As yet there have been no reports of such an attack taking place.
"The first flaw reported fools the browser into thinking software is being installed by a legitimate, or safe, website. The second flaw happens when the software installation trigger does not properly check icon web addresses which contain JavaScript code.
A hacker could potentially take advantage of the security flaws to secretly launch malicious code or programs.
Mozilla advised people to download add-ons to its software manually from the Foundation's site.
Danish security firm Secunia said called the flaws "extremely critical" because cookie and history information could be used to get access to personal information or gain access to sites previously visited."
BBC News
Mozilla has advised users to disable JavaScript code until an update is released.
"The first flaw reported fools the browser into thinking software is being installed by a legitimate, or safe, website. The second flaw happens when the software installation trigger does not properly check icon web addresses which contain JavaScript code.
A hacker could potentially take advantage of the security flaws to secretly launch malicious code or programs.
Mozilla advised people to download add-ons to its software manually from the Foundation's site.
Danish security firm Secunia said called the flaws "extremely critical" because cookie and history information could be used to get access to personal information or gain access to sites previously visited."
BBC News
Mozilla has advised users to disable JavaScript code until an update is released.