Browser bugs hit Firefox and IE7

Two flaws each, claims security researcher

Written by Shaun Nichols in California

Security researchers have warned of new vulnerabilities in Mozilla's Firefox and Microsoft's Internet Explorer

In a posting to the Full Disclosure mailing list, security researcher Michal Zalewski outlined two vulnerabilities in each of the popular browsers. 

The vulnerabilities could allow attackers to overwrite the URL bar, or steal user data and remotely download and execute code.

A Microsoft spokesperson told vnunet.com that that the company is investigating two reported Internet Explorer vulnerabilities, but declined to acknowledge that they were uncovered by Zalewski.

The most serious of the Internet Explorer flaws could allow an attacker to steal cookie files, inject malicious code into web pages and steal sensitive information for IE6 and IE7, according to Zalewski.

The second vulnerability only affects IE 6 and is said to pose less of a risk. The flaw could allow an attacker to spoof Internet Explorer's URL bar, possibly allowing an attacker to disguise phishing or scam sites as a trusted website.

Zalewski said that the more important of the two Firefox vulnerabilities could allow an attacker to inject malicious JavaScript code to log keystrokes.

This vulnerability was confirmed to be a variant of a previously reported flaw on Mozilla's Bugzilla reporting service

The second reported vulnerability uses flaws in the way Firefox handles confirmation dialog boxes.

Zalewski claimed that the vulnerability could allow an attacker to download and execute software without the user's knowledge.

The Bugzilla page for the second reported vulnerability is currently closed to unauthorised users.

Tags:

Further reading

Related articles

Mozilla issues 'critical' Firefox fixes

Update addresses a number of security issues   More...

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Mozilla takes second shot at Firefox flaw

Company issues new update for QuickTime vulnerability   More...

Twin Trojans attack Macs

Malware spotted in the wild   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

18 Jul 2008

7.91 MBPodcast Special: Views from the Valley More...

17 Jul 2008

3.61 MBMalware explosion, nanotech fears and a jailed spammer More...

16 Jul 2008

4.17 MBiPhone 3G hacked, YouTube privacy deal and BT ad complaints More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Computer mouse

Computer mouse heading for extinction

Humble input device being usurped by touch screens and facial...  More...

Sony Vaio SR

Sony unveils Vaio business notebooks

Three new laptops aimed at 'out and about professionals'   More...

Advertisement

Firefox

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Apple iPhone 3G

Hold off on iPhone 3G, says analyst

Corporates should consider new handset a 'beta release'   More...

Advertisement