1. Home
  2. Computing & Technology
  3. Web Browsers
photo of Scott Orgera
Scott's Web Browsers Blog

By Scott Orgera, About.com Guide to Web Browsers

Did Mozilla Rush the Latest Firefox Patch?

Tuesday February 12, 2008

It appears so, as programmer Ronald van den Heetkamp unveiled information about a vulnerability in Firefox 2.0.0.12 mere hours after its release. It seems that a portion of the critical directory traversal flaw addressed in the latest update still exists. In 2.0.0.12, Mozilla corrected the fact that this flaw could be exploited via one of several hundred browser add-ons. However, according to van den Heetkamp, that only fixed half of the issue since Firefox itself can be tricked into traversing directories back. He also discovered an information leak that could lead to an attacker reading your Firefox preferences as well as files stored within the Mozilla program files directory.

There has already been some debate over the seriousness of this leak, with Mozilla's Mike Shaver adamantly stating that it does not expose any personal information. van den Heetkamp fired back, saying that he was wrongfully interpreted and that he never stated it was a personal information leak. "Can it read personal information? Probably under the right circumstances, yes but that is highly theoretical," said van den Heetkamp. Nevertheless, protecting yourself while waiting for Firefox 2.0.0.13 is a good idea. The NoScript extension can do the trick here, and I recommend installing it right away.

(Photo © kirza - #481549/stockxpert)

Comments

No comments yet. Leave a Comment

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Explore Web Browsers
About.com Special Features

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

Easy ways to connect two computers for networking purposes. More >

  1. Home
  2. Computing & Technology
  3. Web Browsers

©2009 About.com, a part of The New York Times Company.

All rights reserved.