• Home
  • Reviews
  • Articles
  • News
  • Tools
  • GamingHeaven
  • Forums
  • Network
 

Go Back   DriverHeaven.net > Forums > News > News

Notices

Reply
 
LinkBack Thread Tools
Old May 10, 2005, 01:54 PM   #1
Everyones life has worth
 
Join Date: May 2003
Location: My Yellow Bug
Posts: 3,778
Rep Power: 42
digerati will become famous soon enough

Mozilla Working on Firefox Fix

The California-based Mozilla Foundation is promising an update soon after two extremely critical security vulnerabilities were found in its Firefox browser.

One flaw, which involves "IFRAME" JavaScript URLs, could be exploited to conduct cross-site scripting attacks and compromise a user's system, PC Pro reported Monday.

A second flaw exists when input passed to the "IconURL" parameter in "InstallTrigger.install()" is not properly verified before being used. It could be exploited to execute arbitrary JavaScript code with escalated privileges via a specially crafted JavaScript URL, experts said.

Because the foundation controls all sites in the default software installation white list, it has been able to take preventative action by placing more checks in the server-side Mozilla Update code and moving the update site to another domain.
______________________________________
Read More/Source: Top-Tech-News
digerati is offline   Reply With Quote


 

 
Powered by: vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
vBulletin implementation by Craig '5320' Humphreys

All times are GMT -5. The time now is 12:45 PM. Copyright ©2008 HeavenMedia.net