September 15, 2002 9:20 PM PDT
Mozilla bug leaks Web surfing data
- Related Stories
-
Mozilla 1.1 debuts to mixed reviews
August 27, 2002 -
Dodging pop-ups with Mozilla
August 14, 2002 -
Mozilla finally turns 1.0
June 5, 2002
![]()
![]()
![]()
![]()
![]()
![]()
Reader Resources
Mozilla 1.0 info![]()
Pop-up downloads![]()
![]()
![]()
![]()
![]()
Researcher Sven Neuhaus, who published a security alert on Wednesday about the issue to the Bugtraq mailing list, said he had confirmed the bug in Mozilla 1.0, 1.0.1 and 1.1, though it probably also existed in older Mozilla versions. It also appears in browsers based on Mozilla's technology, including Netscape 7 and Galeon, a Linux application, he said.
Mozilla is an open-source project initiated by Netscape Communications, now part of AOL Time Warner, to foster volunteer interest in its browser technology. Mozilla's features and its Gecko rendering engine are now used in the Netscape 7 commercial software from AOL Time Warner.
The problem lies with a component called "onunload," Neuhaus said. He created a demonstration exploiting the bug, which he said is several weeks old, hoping to prompt Mozilla developers to deliver a fix.
In the meantime, Neuhaus said the vulnerability can be worked around by switching off JavaScript.
ZDNet U.K.'s Matthew Broersma reported from London.