Welcome | Log In
Security

Mozilla Responds to Security Vulnerability

Print Version
E-Mail Article
Reprints

When Microsoft was experiencing problems, some in the security community, including the SANS Internet Security Center, advised users to consider alternatives like Mozilla and Opera. Now, analysts are saying that any web browser is susceptible to security troubles and everyone needs to have good practices in place, including Linux users.


From Laid-Off to Entrepreneur: Launching a Web Biz on a Shoestring. "That day" has arrived. For whatever reason, the job you’ve been working for years is no longer there for you. Times are tough; people are facing unemployment in droves. In today's economic age, however unfair, it's a reality. What do you do now? [Download PDF: 10 pgs | 558k]

The Mozilla Foundation has issued a patch for a security vulnerability discovered Thursday in the organization's open source Linux MPS Pro Focus on Your Business —  Not Your IT Infrastructure. More about open source Mozilla Application Suite, Firefox browser and Thunderbird e-mail client. The security flaw, known as the "shell exploit," could allow attackers to run programs on Windows XP.

Users of other operating systems, including Mac Consolidate Mac Servers. Run Windows Server on your Mac. Watch a Demo or Download a Trial. OS X, Linux and other Unix variants, would not be affected by the flaw.

The shell exploit can be used to send a file extension into an operating system, and Windows XP will run whichever helper application is related to the extension. With this ability, an attacker could gain access to a system or freeze a computer remotely.

Commitment to Security

According to the Mozilla Foundation, the vulnerability was posted on Thursday to Full Disclosure, a public security mailing list. The same day, the foundation's security team confirmed the report and developed a fix.

On Friday, the team released a configuration change that resolves the problem by explicitly disabling the use of the shell external protocol handler. Instructions on administering the patches can be found on the foundation's site.

The organization has noted that it will continue efforts to release secure products and respond quickly when security vulnerabilities are identified in its software.

It has also announced that future versions of Mozilla Firefox will include automatic update notifications, which will make it easier for users to be alerted to security fixes.

All Browsers Vulnerable?

News of the Mozilla flaw comes after recent reports of an OS X vulnerability and an announcement by the Debian Project of a flaw in the Linux kernel.

Microsoft (Nasdaq: MSFT) More about Microsoft also has been dealing with a spate of security flaws in its Internet Explorer browser in the past few weeks, prompting a software update in early July.

When Microsoft was experiencing problems, some in the security community, including the SANS Internet Security Center, advised users to consider alternatives like Mozilla and Opera. Now that it has been shown that alternative browsers can be just as flawed as the larger players, the whole issue seems to have highlighted the difficulties of keeping browsers secure.

"Previously, what seemed to be a safe haven turned out not to be," said Laura DiDio, Yankee Group analyst, in a LinuxInsider interview. "It shows that if you don't have safeguards in place, you're going to see a problem. This isn't just a Microsoft issue anymore."

Code Violation

Part of the problem, DiDio noted, is the inordinate amount of code that is involved with browsers. She compared the situation to a facial. Although a person might think his or her skin is clear and blemish free, once it goes under a magnifying glass, every flaw is highlighted.

"Software is an inexact science," she said. "The general rule of thumb is that for every hundred lines of code, you have a minimum of three errors. Mozilla has a few million lines of code. It's going to have errors."

"Exposing flaws is important for user trust," said Thomas Kristensen, CTO of Danish security services company Secunia, a firm that has discovered IE holes in the past. "People have to be able to know a browser is behaving the way it should," he told LinuxInsider. "That's why it's important for browser developers to announce these flaws."

DiDio noted that as Linux grows up, users can expect to see more browser vulnerabilities brought to light. She said that although most attackers have been focused on Windows, that does not mean Linux users will be safe for long.

"I think the message here is: Get ready for more flaws," she said. "It's a fact of life that no matter what system you're using, you shouldn't feel secure without having good practices in place."

Social Networking Toolbox:

Print Version E-Mail Article Reprints More by Elizabeth Millard   RSS

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
Free White Papers | Case Studies | Reports
  WiFi Hotspot Locator
City or Zip/Postal Code:
Country/Region:
ECT News Network Information
Locate Products and Services
Corporate
Reader Services
ECT News Network