We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,258 News Articles

Firefox 2.0 users to get important security fix

Mozilla plans bug-fix release for next week

Firefox users will get a bug-fixing update next week to repair a long-standing security flaw in the software.

Mozilla said the 2.0.0.10 update is in testing now and should be released to the public next week, following the Thanksgiving holiday in the US. "We are giving it a couple of days to make sure that there are no issues found and we'll release it after Thanksgiving," said Mike Schroepfer, Mozilla's vice president of engineering.

Mozilla is calling on the Firefox community to test the browser during a quality assurance 'testday' this Friday.

The issue was first reported last February by Jesse Ruderman, but it gained widespread attention earlier this month when researcher Petko Petkov pointed out on his blog that the flaw could be used to launch a cross-site scripting attack against the Firefox browser.

The flaw has to do with the fact that Firefox does not properly check files that are compressed using the Java Archive (.jar) format. Attackers could sneak malicious code into the Jar-compressed documents, which would then be run by the victim.

A few days after Petkov posted his findings, a researcher going by the name 'Bedford' showed how this attack could be launched against Google users, giving them access to victims' Gmail accounts, Google searches and other sensitive data stored on the Google website.

"This means that attackers can get to any place on Google and do whatever they want with your profile and your online presence," Petkov wrote in a blog posting.

Though both Petkov's and Bedford's vulnerabilities are related to the way Firefox handles .jar files, Mozilla considers them to be two separate issues, both of which are set to be patched in next week's 2.0.0.10 release.

Related articles:

Firefox 2 review

For more PC security news, reviews and tutorials, see Security Advisor.


IDG UK Sites

iPhone 6 review: best ever iPhone is very good... but no longer the best phone you can buy

IDG UK Sites

Why Apple and Samsung, Google and Microsoft's schoolyard spats make them all look stupid

IDG UK Sites

How to successfully bridge the gap between clients and creatives

IDG UK Sites

How to update your iPhone or iPad to iOS 8: including how to install iOS 8 if you don't have room ()......