Malicious code in an image could enter PC through browser
Malicious code in an image could enter PC through browser

Mozilla fixes new Firefox flaw

Users urged to download patched version immediately

Written by Iain Thomson

The Mozilla Foundation has released a new security patch for its Firefox internet browser and is urging users to install it.

The patch fixes a flaw in the software that handles animated GIF images that could cause a buffer overflow.

If a hacker embedded malicious code in an image it could conceivably enter a PC through the browser software, although no exploit code has yet been found in the wild.

"The Mozilla Foundation is deeply committed to providing its users with the safest internet experience possible," said Chris Hofmann, director of engineering at Mozilla.

"To deliver our users the experience they deserve, we must stay ahead of the curve in patching potential vulnerabilities. For example, the bug patched in this update has no known real world exploits, and we were able to provide a quick response."

The flaw came to light after work done by security researchers at Internet Security Systems but was fixed before they published their report. This is the second Firefox patch to be released in the past month. The buffer overflow patch is available here.

Tags:

Further reading

Firefox hit with new critical flaws

Holes could allow hackers to implant Trojan or key-logger   More...

Netscape hit by critical flaw

'Use another product,' advises browser firm   More...

Mozilla Bug Bounty pays fault-finders

Users who find flaws offered $500 per bug plus a free T-shirt   More...

Firefox market share rockets

IE5 users might be moving to Firefox not IE6, says web analytics firm   More...

Related articles

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Apple QuickTime exploit goes wild

Streaming media flaw used to push malware   More...

Mozilla takes second shot at Firefox flaw

Company issues new update for QuickTime vulnerability   More...

Mozilla patches cross-browser Firefox flaw

Fix does not cover Internet Explorer problem   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement