|
||
Title: Mozilla bug alert Post by ExplodingEyeBall on Sep 15th, 2005, 10:54am Security Alert, September 15, 2005 Critical Bug in Firefox, Mozilla, and Netscape Browsers Tom Ferris reported a buffer overflow vulnerability in Firefox Web browsers. The vulnerability exists because of faulty URL processing and could lead to the execution of remote code. The problem has been reported to affect Firefox 1.0.6 and Firefox 1.5 Beta, as well as Netscape 8.0.3.3 and Mozilla 1.7.11 because they share Firefox's code base. Previous versions of these browsers might also be affected. A simple workaround prevents the browser vulnerability from being exploited. Mozilla Foundation released a self-installing patch (in an XPI file) that contains a workaround that disables International Domain Name (IDN) processing. The workaround changes a configuration parameter, network.enableIDN, to false. Alternatively, you can enter about:config in the address bar, search for the parameter, and reset it to false. At least one person reported that the same workaround and XPI file can be applied to the Netscape browser. For links to the patch and further details, read this article on our Web site. http://list.windowsitpro.com/t?ctl=13AF5:3CA24 Thank you for subscribing to Security UPDATE. Please tell your friends about this newsletter and alert list! This email newsletter is brought to you by Windows IT Security, the leading publication for IT professionals securing the Windows enterprise from external intruders and controlling access for internal users. Subscribe today. http://list.windowsitpro.com/t?ctl=13AF4:3CA24 |
||
Title: Re: Mozilla bug alert Post by pattik on Sep 15th, 2005, 11:12am Thanks, Pat. I don't understand it, but I installed the patch. Thanks ;;D |
||
Title: Re: Mozilla bug alert Post by rextangle on Sep 15th, 2005, 2:02pm Thanks Pat! [smiley=thumbsup.gif] |
||
Title: Re: Mozilla bug alert Post by Jasmyn on Sep 16th, 2005, 8:32am Thanks exploding balled eye guy! ;) |
||
Clusterheadaches.com Message Board » Powered by YaBB 1 Gold - SP 1.3.1! YaBB © 2000-2003. All Rights Reserved. |