Language Selection

English French German Italian Portuguese Spanish

Flaw found in Firefox

Filed under
Security

Firefox versions 1.0.1 and 1.0.2 contain the vulnerability, the security information company said in an advisory on Monday. The flaw stems from an error in the JavaScript engine that can expose arbitrary amounts of heap memory after the end of a JavaScript string. As a result, an exploit may disclose sensitive information in the memory, Secunia said.

"Unlike other browser flaws, this one is not subject to phishing or access to the system. But it can expose sensitive information from other Web sites you visited and the information you entered there," said Thomas Kristensen, Secunia chief technology officer.

While the flaw is only rated as "moderately critical" by Secunia, the rapid adoption of the open-source browser means that many users may be at risk. Prior to the release of version 1.0, downloads of earlier versions of the browser had reached 8 million within the first 18 months.

The Mozilla Foundation, which makes the Firefox browser, is working on a patch, and no cases have been reported, a representative for the group said.

Secunia has developed a test that allows people to see whether their system is affected by the vulnerability.

Source

More in Tux Machines

Open source software is for everyone – so where are the women?

We all know that there is a diversity problem in tech. The depressing stats from numerous reports and studies all point to stereotypes and bias hitting young girls’ perceptions of STEM negatively, with this sitting alongside poor retention figures and a lack of women at the board level. However, one particular branch of tech may be struggling in more when it comes to diversity and inclusion – the one branch, in fact, which has inclusiveness at the very core of its ethos. Read more

Google launches new site to showcase its open source projects and processes

Google is launching a new site today that brings all of the company’s open source projects under a single umbrella. The code of these projects will still live on GitHub and Google’s self-hosted git service, of course, with the new site functioning as a central directory for them. While this new project is obviously meant to showcase Google’s projects, the company says it also wants to use it to provide “a look under the hood” of how it “does” open source. Read more

Tizen and Android

Day of Infamy, CRYENGINE, and Performance Tools