We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
79,864 News Articles

Mozilla forced to fix Firefox

17 holes patched in latest upgrade

Several security vulnerabilities in Firefox and the Mozilla Suite of internet software put users of the open-source products at risk of hacker attacks, the Mozilla Foundation warned Thursday.

The organisation released Firefox 1.0.1, which fixes 17 security flaws in the popular web browser. The most serious flaws could allow an attacker to gain full control over a victim's PC, the Mozilla Foundation said in a statement. Firefox 1.0 was released in November and has since been downloaded more than 27m times.

Firefox 1.0.1 also includes several fixes to guard against spoofing of web addresses and the security indicator on websites. These vulnerabilities could be exploited for phishing scams, which typically use spam email messages to drive people towards fraudulent web pages that look like legitimate e-commerce sites.

One of the changes made in Firefox 1.0.1 is in the way the browser handles international domain names (IDNs). These names are now displayed differently to make it easier to spot spoofed websites. Because of the way Firefox displayed IDNs, it was possible to register domain names with international characters that resembled other common characters, thus tricking users into believing they were on a trusted website.

For protection against possible exploitation of the security flaws, users should download and install the latest version of Firefox, the Mozilla Foundation said. The organisation does not offer patches to fix the problems without having to install a new browser.

Most of these flaws also affect the Mozilla Suite, which includes a Web browser, an email client, Internet Relay Chat client and web page editor. However users of the suite are left vulnerable because no fixes are yet available. Mozilla 1.7.6, the update that fixes the issues, is due out in "a couple of weeks," according to a Mozilla Foundation spokesman.

The public warning of the security vulnerabilities is evidence that the Mozilla Foundation's products give a false sense of security, said Thor Larholm, a senior security researcher with PivX Solutions.

"The only reason Mozilla and Firefox have a good track record in security with a low number of security vulnerabilities is simply because they don't tell anyone about them," Larholm said.

"The Mozilla Foundation has fixed hundreds if not thousands of security vulnerabilities over the last few years without notifying the world and without providing security patches, instead they have simply just told their users to upgrade," he said. "We have to remember that all software has security vulnerabilities, the only difference is in how we anticipate them and inform the world about their existence."


IDG UK Sites

45 Best Android games: top Android games for your smartphone or tablet in 2014 (24 are free!)

IDG UK Sites

How Apple, Adobe, Microsoft and others have let us down over UltraHD and hiDPI screens

IDG UK Sites

Do you have the X-Factor too? Mix Off app puts fans in the frame

IDG UK Sites

iPad Pro release date, rumours and leaked images - 12.9 screen 'coming in 2015'