internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
QuickTime for Windows
Ad-Aware 2008 Free
Internet Explorer 8
Adobe Flash Player
Paint Shop Pro
Windows Live Suite
AVG Anti-Virus Free
Winamp
Spybot Search and Destroy

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

New Firefox Vulnerability Pushes Latest Update
Newly Identified Vulnerability Patched in Firefox 1.0.1
Sean Michael Kerner

If you're a Mozilla Firefox user, there's another reason for you to update to the latest version of the upstart browser released last week.

Buried in the list of Firefox security updates is a critical heap overflow issue that hit the public disclosure lists officially just today.

Security firm iDefense issued a public advisory today titled, "Mozilla Firefox and Mozilla Browser Out Of Memory Heap Corruption Design Error." The vulnerability could allow an attacker to execute arbitrary code and/or crash the browser.

According to iDefense's security disclosure timeline, the vulnerability was reported to the Mozilla Foundation on Feb. 9, and Mozilla responded that day. "Coordinated" public disclosure was supposed to occur today.

The vulnerability involves the remote exploitation of a "design error" that could potentially allow a malicious remote miscreant to trigger a heap (define) corruption.

According to the iDefense advisory, the vulnerability specifically exists in string-handling functions. The flaw involves the way those functions handle memory, which could potentially allow memory to be overwritten in a fixed location if, during string growth, memory reallocation fails.

According to Mozilla's advisory, "creating the exact conditions for Exploitation — including running out of memory at just the right moment — is unlikely."

That said, iDefense's advisory notes that the two items required to execute the exploit — knowing the browser version and being able to cause memory exhaustion — are entirely plausible. The security firm wrote in its advisory that the memory exhaustion could be triggered by a JavaScript ("to allocate enough memory to trigger this vulnerability") or even compressed data.

According to iDefense, even a failed exploitation attempt could result in the browser crashing. A successful exploitation attempt would allow for arbitrary code execution with the same privileges of the logged-in user. Mozilla's update last week supposedly fixes the issue.

Firefox's security concerns come amid new reports of the open source browser's growing market share. According to Web analytics firm OneStat.com, Mozilla browsers, including Firefox, now command an 8.45 percent market share. This is up from November when its share was only 7.53 percent. Microsoft's Internet Explorer still dominates at 87.28 percent.

"It seems that global usage share of Mozilla's Firefox is still increasing, and the total global usage share of Microsoft's Internet Explorer is still decreasing," said Niels Brinkman, co-founder of OneStat.com, in a statement. "It looks like that browser users of Internet Explorer 5 are switching to Mozilla Firefox instead of upgrading to Internet Explorer 6.0."

News courtesy of internetnews.com

March 1, 2005

Download Mozilla Firefox Now!Download

Download Internet Explorer Now!Download

View All Web Browsers

Contents:
1. Newly Identified Vulnerability Patched in Firefox 1.0.1


Additional Articles:

  • Mozilla's Newest FireFox Takes Flight
  • Browser Wars v.2004: Part 1
  • Browser Wars v.2004: Part 2
  • Mozilla Firefox's Volunteer Launch Brigade
  • Rise of the Underdog Browser
  • Firefox Makes It Official
  • Add-ons Extend Firefox Growth
  • Getting the Most Out of Firefox
  • Firefox Thankful for Strong November
  • Firefox, Others at Phishing Risk
  • Browser Wars: Who's Winning, Who's Losing
  • Firefox Torches Competition for Enterprise Linux Award
  • Mozilla Updates Firefox
  • Firefox Update Patches Three in Time
  • JavaScript Flaw Hits Mozilla Users
  • Firefox Popularity Spurs Mozilla Traffic Surge
  • Beware the Browser Backlash
  • Another Flaw Found in Mozilla
  • Google Extends Firefox
  • New Firefox Fixes Holes
  • Firefox Advocate Site Hit by Hackers
  • Mozilla Goes for More Green
  • IBM Donates Code to Firefox
  • Firefox Losing Its Grip?
  • Mozilla Under Fire
  • Mozilla FireFox DoS Exploit Code Released
  • Firefox: Nearly a Year Old And Now 100M Strong
  • Happy Birthday, Firefox 1.0
  • Firefox Upgrade Near
  • Firefox at Critical Mass?
  • New Firefox Kills Bugs
  • A Word-Wise Firefox Extension
  • Mozilla Plugs Firefox Bugs
  • FireFox Fixes by the Dozen
  • Goooaaal! Google, Mozilla Kick In Soccer Fix
  • Firefox 2.0: Mozilla's Tabs Overfloweth
  • Firefox 1.5.0.5 Fixes JavaScript Flaws
  • Firefox Is Doing So Well It's Now a Malware Target
  • Firefox 2.0 Beta Tweaking Its Look
  • The Firefox, IE Race to The Finish
  • Firefox Hits Seventh Heaven
  • Firefox 2.0 Release Candidate Goes Live Today
  • Double Deuce as Firefox 2.0 Nears Completion
  • Mozilla Fine-Tunes for Final Release of Firefox 2
  • Firefox 2.0 Released: 'Bon Echo' Lives!
  • Firefox 3.0 Already?
  • Path to Firefox 2.0 Is Cleared
  • Our Phishing Filter Is Better Than Yours!
  • Phishers Lurk for Firefox 2.0 Password Manager
  • Mozilla Fixes Firefox Flaws, Misses One
  • Mozilla Rakes In $53M
  • Mozilla Patches Some Firefox Holes
  • Mozilla Security: More Than Meets the 'Aye'
  • One Flaw and a First for Latest Firefox Update
  • Firefox 1.5 Gets Its Last Update
  • Firefox at Risk Because of Internet Explorer?
  • Firefox Fixes IE Flaws
  • Mozilla Firefox Still at Risk
  • Will Mozilla's Fuzzer Break the Web?
  • Mozilla Updates Firefox Ahead of Black Hat
  • Flaw Still Shadows Firefox
  • Firefox Gets BitTorrent
  • Firefox Gets QuickTime Fix
  • Mozilla Separating Browser from the App
  • Firefox Fixes Cross-Site Flaws
  • Firefox Breaks Web Canvas
  • Warning on Spoofed Login Windows in Firefox
  • Mozilla Update Quashes Slew of Firefox Flaws
  • Firefox Update Tackles Pair of Critical Bugs




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers