NOW READ THIS
("Security Advisory")
Go Back
Submitted by: Bill Hickey
NCVA List Master
NRT-0272 Mozilla Fixes Another Firefox Protocol-Handling Bug:
Mozilla Corporation updated their Firefox browser for the second time this month to patch a pair of vulnerabilities, including yet another flaw in how it parses malformed URLs that can call up other applications. Firefox 2.0.0.6 includes a fix for a bug disclosed by a pair of researchers a week ago. This reduces the risk of malicious data being passed through Firefox to another application that may then trigger unexpected and potentially dangerous behavior. The second vulnerability patched by 2.0.0.6 was a bug rated "moderate" that involved certain Firefox add-ons that create about:blank web pages.
(ComputerWorld 31JUL07)
Last Modified: Tuesday, 07-Aug-2007 21:10:01 EDT