Firefox
The Firefox vulnerability lies in the way it handles JavaScript code in QuickTime files

Mozilla takes second shot at Firefox flaw

Company issues new update for QuickTime vulnerability

Written by Shaun Nichols in California

Mozilla has issued a new fix for a Firefox vulnerability which it had supposedly patched in July.

The vulnerability lies in the way Firefox handles JavaScript code in QuickTime files, such as .mov and .mp3. Malicious code could be disguised as a media file which would be launched in Firefox via QuickTime.

The code would then be able to run with the privileges of the current user, possibly leading to a malware installation or data theft.

The flaw was originally reported in July as a cross-browser attack between Internet Explorer and Firefox. Mozilla reacted quickly, issuing a fix four days later.

However, security researcher Petko D. Petkov found that neither Apple nor Mozilla had completely plugged the hole, and that Firefox remained vulnerable to a serious attack. Petkov posted code and working samples of the attack in a blog entry.

Mozilla noted that the latest fix will prevent attackers from executing the commands that could allow for full system access and remote code execution.

But the company warned that the QuickTime issue remains, and that the flaw could still be used to flood users with pop-ups and dialogue boxes.

Spokespersons for Apple did not immediately return a request for comment. The company does not normally discuss security issues until a fix has been released.

Petkov said that Internet Explorer 7 was also found to be vulnerable, but noted that the browser's security controls limit the effectiveness of the attack. Internet Explorer 6 is not affected.

Tags:

Further reading

Mozilla Firefox 2.0.0.16

Minor update to the web browser   More...

Mozilla readies launch of Thunderbird spin-off

Foundation to develop internet comms apps based on Thunderbird brand   More...

Mozilla toasts 400m Firefox downloads

Microsoft rival still gaining ground in the browser wars   More...

Related articles

Apple patches QuickTime flaw

Windows vulnerability allowed scripted attacks   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Google plugs Gmail security hole

Filter-injection attack allowed forwarding of emails to third parties   More...

Mozilla issues 'critical' Firefox fixes

Update addresses a number of security issues   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement