Security Issues in Mozilla 454
paulius_g writes "SecurityFocus has released a security warning with three problems that affect Mozilla on all platforms. The first issue allows the source of a download to be spoofed, generating a fake URL. This security issue is really easy to replicate: Create a long URL and the downloading box will only display its ending (Mozilla and Firefox). The second issue was created by the way that Mozilla's browsers handle news:// links to newsgroups, hackers can easily create false links and create a buffer overflow (Mozilla 1.7.5 and below, Firefox versions before 1.0). The third exploit affects machines with multiple users. The way that Firefox and Thunderbird store files allows every user to see them and to probably catch the other user's surfing habits (Firefox and Thunderbird). Let's hope that these will be fixed soon!"
Only THREE? (Score:3, Funny)
Security (Score:5, Funny)
Not Mozilla!! (Score:5, Funny)
Bet Gates is grinning today hoping everyone will forget his laptop crash.
Don't Tech all day and night, visit:
WillingtonKarateClub.org Training Tips and more
3 Whole Security Issues! Thank God... (Score:5, Funny)
Re:I bet they will be fixed within 24hours! (Score:1, Funny)
-- xutopia
Jeebus Kriced (Score:5, Funny)
Re:Umm.... (Score:5, Funny)
Re:Even then.... (Score:1, Funny)
These flaws are a real problem but Firefox, YES, is still better than IE. Besides, the first flaw is not a flaw: you must ALWAYS download stuff from people you trust (and even then , you have to check the sources with a GnuPG key ring).
Re:Even then.... (Score:1, Funny)
Re:Even then.... (Score:1, Funny)
Re:A fix? (Score:3, Funny)
Long URL? (Score:3, Funny)
is this long enough?
Re:A fix? (Score:3, Funny)
Re:Yipee (Score:2, Funny)
Never download Mozilla with IE or any other insecure product! Only download Mozilla with Mozilla!
If you download it with IE you may not be downloading the REAL Mozilla. That's what I tell people who report Mozilla crashing and stuff like that. The real Mozilla is flawless. How do you know you are using the real Mozilla?
Also never let someone else install Mozilla from a storage device. They may have tampered with it.
Remember: It's an open source product, so anyone can recompile it with his own malware embedded!
1. Is there a patch or do I have to download the whole browser and reinstall?
See Tools>Options>Software Updates
Re:Security (Score:1, Funny)
Re:Misleading Article (Score:5, Funny)
You must be new here.