April 5, 2005 2:24 PM PDT

Flaw found in Firefox

A flaw has been discovered in the popular open-source browser Firefox that could expose sensitive information stored in memory, Secunia has warned.

Firefox versions 1.0.1 and 1.0.2 contain the vulnerability, the security information company said in an advisory on Monday. The flaw stems from an error in the JavaScript engine that can expose arbitrary amounts of heap memory after the end of a JavaScript string. As a result, an exploit may disclose sensitive information in the memory, Secunia said.

"Unlike other browser flaws, this one is not subject to phishing or access to the system. But it can expose sensitive information from other Web sites you visited and the information you entered there," said Thomas Kristensen, Secunia chief technology officer.

While the flaw is only rated as "moderately critical" by Secunia, the rapid adoption of the open-source browser means that many users may be at risk. Prior to the release of version 1.0, downloads of earlier versions of the browser had reached 8 million within the first 18 months.

The Mozilla Foundation, which makes the Firefox browser, is working on a patch, and no cases have been reported, a representative for the group said.

Secunia has developed a test that allows people to see whether their system is affected by the vulnerability.

10 comments

Join the conversation!
Add your comment (Log in or register)
already fixed, soon
Firefox 1.03 coming out within days, this already fixed.

Running an Aviary of 1.03 right now.
Posted by xpgeek11 (12 comments )
Reply Link Flag
That is just wrong...
It may soon be fixed. It may be fixed, but the solution is not available for general download. They may fix it soon.
Please pick the one you like.
Posted by catchall (246 comments )
Link Flag
"Already fixed, soon"?
Oh please, just because you want to defend your favorite browser, you still need to study your grammer and write properly, right? :)
Posted by 201293546946733175101343322673 (722 comments )
Link Flag
The release candidate of version 1.0.3...
... can be found here:
<a class="jive-link-external" href="http://weblogs.mozillazine.org/asa/archives/007896.html" target="_newWindow">http://weblogs.mozillazine.org/asa/archives/007896.html</a>

It's not yet final, but if you are really worried about this flaw, you can get this version.
Posted by feranick (211 comments )
Reply Link Flag
This is news
When a IE/XP flaw is found, that just means it is a new day.

When a FF flaw is found it is news as it is a faily uncommon event. Of course. they have a release candidate up and running. While Microsoft would be waiting until the next patch cycle, at the minimum.

Sure, it would have been better if this flaw did not exist, but no one can claim that Mozilla is not pro-active and quickly react to any problems.
Posted by pcLoadLetter (395 comments )
Reply Link Flag
I'm confused
By your angle since Microsoft flaws are so common then they are not news worthy. It seems to me you are making a case for Firefox flaws to reciveve greater attention.

Eitherway, it is news. Microsoft is attacked for flaws in Win98, so it is fair that Firefox is attacked for flaws in their current "stable" version.

(Incidently I use Firefox... at the moment. I find the whole "one tab is busy they all are" feature/flaw annoying.)
Posted by Andrew J Glina (1673 comments )
Link Flag
Firefox Flaw
Wow. More people are using it, and flaws are starting to appear. What a concept.
Posted by (3 comments )
Reply Link Flag
Huh...
Huh... isn't that odd...?

;)
Posted by David Arbogast (1712 comments )
Link Flag
Flawed Perseption
I find it amusing that we all have resorted to pointing out flaws in software. Mozilla never said their wouldn't be flaws. I don't think Microsoft said anything like that either. Flaws are an inevitable part of anything. I think many have made that point over and over again.

I am amazed at the sides people take. It doesn't really have to do with the quality of software it's more about who is right and who is wrong.

It's true that the more people using a peice of software (firefox in this case) the more flaws are going to be found. The real issue is how bad are they, how fast do they get fixed, and how is the fix implemented. I will be honest with you, I don't like redownloading the entire program to fix a flaw. In my opinion it's like rereading the dictionary to find a single word. With the software it maybe the best bet, but it's still annoying. On the other hand I find that I like firefox better than other browsers and so I make a compremise on how it's patched.
Posted by System Tyrant (1453 comments )
Reply Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (-0.69%) -89.23 12,801.23
S&P 500 (-0.69%) -9.31 1,342.64
NASDAQ (-0.80%) -23.35 2,903.88
CNET TECH (-0.58%) -11.91 2,032.01
  Symbol Lookup