Mozilla seals off URI flaws again

Firefox update fixes vulnerabilities in resource handler

Written by Shaun Nichols in California

Firefox developers have released a security update that they hope will fix a lingering security threat in the popular open source browser.

The Firefox 2.0.0.6 update fixes a problem in the way Firefox handles the uniform resource indicators (URI) that are used to launch other applications when an unsupported file type is loaded.

The URI vulnerability was originally discovered as a "cross-browser" flaw in which an attacker could use a specially crafted internet address in Internet Explorer to launch Firefox without security protections and run malicious code.

Mozilla had attempted to fix the flaw in the 2.0.0.5 update, claiming that any further fixes would be the responsibility of Microsoft.

Following the 2.0.0.5 release, however, security researcher Jesper Johansson pointed out that the URI handler in Firefox remained just as vulnerable as Internet Explorer. The problem, noted Johannson, was that Firefox did not properly format the URI address, allowing an attacker to potentially insert multiple malicious instructions.

In addition to fixing the way URI addresses are displayed, the 2.0.0.6 update also repairs a vulnerability that would allow an attacker escalate privileges through a specially crafted about:blank window. That vulnerability is listed as "moderate," the second of Mozilla's four alert levels.

No other security or performance fixes were included in the update.

Tags:

Further reading

Related articles

Microsoft comes clean on URI holes

Company vows to fix address handling flaw   More...

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Mozilla takes second shot at Firefox flaw

Company issues new update for QuickTime vulnerability   More...

Mozilla issues 'critical' Firefox fixes

Update addresses a number of security issues   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement