Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Advisories

September 5th, 2007, 13:55 GMT · By Alexandru Dumitru

Firefox Still Vulnerable! (Reminds Me Of XP)

SHARE:

Adjust text size:



Enlarge picture
It still can't properly handle protocol. It's bugged! They've released two patches since these flaws were first discovered but it is still vulnerable.
This is sort of like Windows XP. They've released it and then came
Service Pack I and then II and a lot of hotfixes and updates and so on and so forth. And now, no matter what version of Windows XP you have, once in a while, that little box pops up in the corner saying some update is available - and I go "What the hell?!" then I see it fixes some flaw. I guess that some programs will always be bugged!

I've got used to Windows, but I hope that Firefox will be something different and once they patch it up it will be for good!
The thing is that Firefox is still vulnerable to attacks exploiting protocol handling bugs, and yes, this should have been fixed in the patches from July... The problem, of course, is still regarding URIs.

I've checked out Billy Rios' blog (this guy is a security expert) and this is how he regarded this issue: "Once again, these URI payloads can be passed by the mailto, nntp, news, and snews URIs, allowing us to pass the payload without any user interaction. So, it seems that although the conditions which allowed for remote command execution in Firefox 2.0.0.5 have been addressed with a security patch, the underlying file type handling issues which are truly the heart of the issue have NOT been addressed."

If you want to pay Rios' blog a visit be my guest and click on this link If this guy doesn't know what he's talking about, then I don't know who does!

I hope that after this, the Mozilla people will treat such problems more carefully and properly attend to bugs! I don't want to see them pull an "XP" on us all!
FILED UNDER:
firefox
bug
vulnerable
URI

TELL US WHAT YOU THINK:

979 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Firefox Receives Softpedia User's Choice Award

Firefox - Dead Browser Walking!

Firefox Is Getting Mac OS X-native Controls

Internet Explorer 7 No Match for Firefox 2.0

Firefox vs. IE Battle - Mozilla Reloaded!

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM