NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Microsoft and Mozilla Plug Critical Holes in Internet Explorer 7 and Firefox 2.0

This February

By Marius Oiaga, Technology News Editor

13th of February 2008, 12:27 GMT

Adjust text size:



Enlarge picture
When it comes down to the face-off between Microsoft and Mozilla on the browser market it's not all about the install base, market share percentages and audience converting, but also about security. And one aspect of the security race, of course not relevant onto itself for the entire protection level delivered by the two browsers, is the vulnerability count. In February, both Microsoft and Mozilla tended to their respective products, patching Critical holes in both Internet Explorer 7 and Firefox 2.0.

Mozilla was first having released the Firefox 2.0.0.12 security
and stability update since February 7. Firefox 2.0.0.12 is designed to plug no less than 10 security vulnerabilities three of which Critical, flaws which permitted "web browsing history and forward navigation stealing, Privilege escalation, XSS, Remote Code Execution, and crashes with evidence of memory corruption," in the eventuality of successful exploits. A single security vulnerability was labeled with a severity rating of high, due to the fact that it permitted "directory traversal via chrome: URI," Mozilla explained. Firefox 2.0.0.12 can be grabbed here.

Microsoft has also had to hammer away at Internet Explorer 7 this month, with Microsoft Security Bulletin MS08-010 - Critical Cumulative Security Update for Internet Explorer (944533). But unlike Mozilla which only offers support for Firefox 2.0, the Redmond company had to deal with no less than four vulnerabilities across multiple versions of IE, and across multiple platforms.

"This update addresses 4 remote code execution vulnerabilities. This security update addresses these vulnerabilities by modifying the way Internet Explorer handles HTML and validates data, as well as by setting killbits for an ActiveX control," explained Terry McCoy, Program Manager Internet Explorer Security. "This update is rated 'Critical' for IE5.01, IE6 Service Pack 1 on Windows 2000, IE6 on Windows XP, IE7 on Windows XPSP2 and IE7 in Windows Vista, IE6 on Windows Server 2003, and IE7 on Windows Server 2003."

Microsoft has patched a total of three security holes considered Critical including vulnerabilities involving HTML Rendering Memory Corruption, Property Memory Corruption, Argument Handling Memory Corruption. The remaining Important flaw is related to ActiveX Object Memory Corruption.

"The IE Cumulative Security Update for February 2008 is now available via Windows Update. Alternatively, you can receive this and all other Microsoft updates via the new Microsoft Update. I encourage you to upgrade to Microsoft Update if you haven't already to ensure that you receive the latest updates for all Microsoft products," McCoy added.

TAGS:

IE7 | Internet Explorer | Firefox 2.0 | Mozilla | Microsoft


Rating:
Good (3.1/5) 6 vote(s) so far    

Read by 994 user(s) | Add comment | Link to this article
Subscribe to news | Print article | Send to friend

© Copyright 2001-2008 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Firefox 3.0 Beta 3 Around the Corner - Firefox 3.0 Beta 4 Confirmed

Firefox Is Slaughtering Internet Explorer

Firefox: 600 Million Add-on Downloads - and Internet Explorer?

IE7 and Firefox 2.0 Are Slaughtering Internet Explorer 6

Mozilla: Firefox 3.0 Beta 3 Release Candidate (RC) Available for Download

Office Live Evolves with New Tools and Features, Embraces Firefox 2.0

With IE8 and Firefox 3.0 in Sight Microsoft Initiates the Final Push of IE7

Firefox 3.0 Beta 3 Available for Download

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 






SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM