Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Internet Explorer

July 25th, 2007, 09:02 GMT · By

Mozilla: Firefox Just As Vulnerable As Internet Explorer

SHARE:

Adjust text size:



Enlarge picture
Mozilla is right on track to dispelling the customer perception created around its open source browser, that the product is an epitome of security. Instead, thanks to a new perspective from Mozilla's chief security officer, Firefox no longer represents an apex of user protection but it is just as flawed as Microsoft's Internet Explorer is. This is how the position of Mozilla security chief Window Snyder can be interpreted at the end of a controversial
guilt game between the open source Foundation and the Redmond Company over a critical security vulnerability affecting IE users via Firefox.

The Microsoft Internet Explorer FirefoxURL Protocol Handler Command Injection vulnerability is shared by both IE and Firefox. When initially discovered the flaw was belied to be associated with Internet Explorer and the way that Microsoft's browser managed registered URL protocols. The vulnerability allowed an attacker to invoke Firefox and then pass the URL to a malicious webpage to the open source browser. Although Mozilla patched the security vulnerability in Firefox 2.0, it claimed that IE7 was also impacted by the critical flaw, while its own browser was not at fault.

In the meantime, Snyder has changed her tune. Following new information unearthed over the weekend, it appears that Firefox 2.0 and Internet Explorer are equally vulnerable. "Internet Explorer was the entry point and Firefox was the application receiving the bad data. We learned about a new scenario that identifies ways that Firefox could also be used as the entry point. While browsing with Firefox, a specially crafted URL could potentially be used to send bad data to another application. We thought this was just a problem with IE. It turns out, it is a problem with Firefox as well. We should have caught this scenario when we fixed the related problem in 2.0.0.5. We believe that defense in depth is the best way to protect people, so we're investigating it now," Snyder stated.

TELL US WHAT YOU THINK:

1,563 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Internet Explorer Killed Firefox and Safari

Mozilla Recommends Firefox 2.0 and Not Internet Explorer 7

New Release of Firefox 3.0 Gran Paradiso in Response to Apple's Safari 3.0 on Windows

IE Down on All Fronts! Users Switching to Firefox

IE7, Firefox 2.0 and Safari 3.0 Share Security Vulnerability on Windows Vista

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM