May 20, 2005 11:00 AM PDT

Netscape patches 1-day-old browser

Related Stories

Netscape update takes aim at phishing

May 19, 2005

Firefox growth slows again

May 10, 2005
A day after launching Netscape 8 and touting the browser's security features, Netscape has released an update to fix several serious security flaws.

The original Netscape 8, released early Thursday, is based on version 1.0.3 of the open-source Firefox browser. Netscape thought the new browser was immune to security vulnerabilities in the Firefox software that were fixed last week in Firefox 1.0.4. It turns out Netscape 8 is vulnerable.

"We had been misinformed by an external security vendor that the Firefox security issues did not affect us," Netscape spokesman Andrew Weinstein said Friday. "Within hours of discovering that the vendor was not accurate, we had addressed those issues and posted an updated version of the browser."

Late on Thursday, the software maker posted Netscape version 8.0.1, which includes fixes for the problems. It plans to push an update out to people who installed the original Netscape 8. However, the company is still working on its update mechanism, so in the meantime people have to go to the Netscape.com Web site to get the patched browser, Weinstein said.

The update is designed to address flaws that were detailed in three security advisories released last week by the Mozilla Foundation, the developer of the Firefox browser. The most serious issues could allow malicious attackers to gain complete control over a victim's PC, according to the advisories.

Netscape, a division of Time Warner's America Online subsidiary, is facing heat over the security goof-up from Mozilla developers. Ben Goodger, lead engineer for Firefox, on Thursday posted an exploit on his blog to demonstrate that Netscape 8 is vulnerable. At the same time, he pitched Firefox as a more secure Web browser.

"If security is important to you, this demonstration should show that browsers that are redistributions of the official Mozilla releases are never going to give you security updates as quickly as Mozilla will itself for its supported products," Goodger wrote.

Netscape 8 includes features to protect users against online scams such as phishing and spyware. The updated browser automatically adjusts security settings while people surf, based on lists of sites that are known to be malicious and of trusted sites.

10 comments

Join the conversation!
Add your comment
Keep it up Mozilla
"Netscape, a division of Time Warner's America Online subsidiary, is facing heat over the security goof-up from Mozilla developers. Ben Goodger, lead engineer for Firefox, on Thursday posted an exploit on his blog to demonstrate that Netscape 8 is vulnerable. At the same time, he pitched Firefox as a more secure Web browser."

I use and really like Firefox, but if this is any indication of how Mozilla developers are going to act when they get competiton then I may just move on. And then to post an exploit to a problem that exist in another form of it's browser is just bad form. That man should be ashamed of himself.

I don't care how secure Firefox is or isn't, but if you have to post exploits to show how great you are then you have no greatness at all. And think of how many people are probably still on ver 1.0.3 of Firefox. Good Job Jerk.
Posted by System Tyrant (1453 comments )
Reply Link Flag
Netscape not playing nice!
Though I don't see Netscape and Firefox rivaling, it is quite
disheartening to see Netscape not releasing a Mac and/or Linux
version of NS 8. Of course most people are stuck on the IE hooks
being the case, which is not the case since Netscape could release
NS 8 for Mac and Linux without the IE integration.

It's not good PR for Netscape to be deserting some of its (non-
Windows) user base.
Posted by JuggerNaut (860 comments )
Link Flag
because security bug details are hidden
[i]"If security is important to you, this demonstration should show that browsers that are redistributions of the official Mozilla releases are never going to give you security updates as quickly as Mozilla will itself for its supported products," Goodger wrote.[/i]

If you've ever used Bugzilla (the bug reporting system of Firefox and Mozilla), you'll know that when *security* bugs are reported, they are hidden from public view (marked with a security flag) until they are fixed. You can't blame a derivative product from being unable to fix the security bugs if the details are hidden from them! Here, Ben Goodger's comparison on security is a red herring, since he uses his exclusive control over the access of information as a reason to criticize his competitors.
Posted by nrlz (98 comments )
Link Flag
Keep it up Mozilla
"Netscape, a division of Time Warner's America Online subsidiary, is facing heat over the security goof-up from Mozilla developers. Ben Goodger, lead engineer for Firefox, on Thursday posted an exploit on his blog to demonstrate that Netscape 8 is vulnerable. At the same time, he pitched Firefox as a more secure Web browser."

I use and really like Firefox, but if this is any indication of how Mozilla developers are going to act when they get competiton then I may just move on. And then to post an exploit to a problem that exist in another form of it's browser is just bad form. That man should be ashamed of himself.

I don't care how secure Firefox is or isn't, but if you have to post exploits to show how great you are then you have no greatness at all. And think of how many people are probably still on ver 1.0.3 of Firefox. Good Job Jerk.
Posted by System Tyrant (1453 comments )
Reply Link Flag
Netscape not playing nice!
Though I don't see Netscape and Firefox rivaling, it is quite
disheartening to see Netscape not releasing a Mac and/or Linux
version of NS 8. Of course most people are stuck on the IE hooks
being the case, which is not the case since Netscape could release
NS 8 for Mac and Linux without the IE integration.

It's not good PR for Netscape to be deserting some of its (non-
Windows) user base.
Posted by JuggerNaut (860 comments )
Link Flag
because security bug details are hidden
[i]"If security is important to you, this demonstration should show that browsers that are redistributions of the official Mozilla releases are never going to give you security updates as quickly as Mozilla will itself for its supported products," Goodger wrote.[/i]

If you've ever used Bugzilla (the bug reporting system of Firefox and Mozilla), you'll know that when *security* bugs are reported, they are hidden from public view (marked with a security flag) until they are fixed. You can't blame a derivative product from being unable to fix the security bugs if the details are hidden from them! Here, Ben Goodger's comparison on security is a red herring, since he uses his exclusive control over the access of information as a reason to criticize his competitors.
Posted by nrlz (98 comments )
Link Flag
Gosh, can you believe it?
Wow, I guess developing secure software just isn't as easy as everyone thought, huh?

And this is when Netscape has a vanishingly small market share. Imagine the potential mess should they ever garner any actual market share.
Posted by (127 comments )
Reply Link Flag
Gosh, can you believe it?
Wow, I guess developing secure software just isn't as easy as everyone thought, huh?

And this is when Netscape has a vanishingly small market share. Imagine the potential mess should they ever garner any actual market share.
Posted by (127 comments )
Reply Link Flag
Fire Molly Wood
Fire Molly Wood.
Posted by montgomeryburns (109 comments )
Reply Link Flag
Fire Molly Wood
Fire Molly Wood.
Posted by montgomeryburns (109 comments )
Reply Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

ie8 fix

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

ie8 fix