Welcome | Sign In
CRMBuyer.com
Applications

Firefox Experiences Its Own 'Patch Tuesday'

Print Version
E-Mail Article
Reprints
Firefox Experiences Its Own 'Patch Tuesday'

Microsoft's and Mozilla's approaches to distributing patches are about as different as their software development strategies. Microsoft's approach stores up patches to release once a month. Mozilla's approach is to release patches as quickly as possible.


To thrive in today’s highly competitive business environment, you need innovative approaches to attract and retain customers. Click here to see how Salesforce.com, West Marine, and VForce-AAA Ohio use LiveOps to optimize their customer experiences.

The Mozilla Foundation yesterday urged users to download the latest security update to Firefox, its popular open-source Web browser.

Firefox 1.0.5 is a security update that addresses several bugs and makes improvements to the software's stability, according to Mozilla. In all, the new version addresses 12 vulnerabilities, including Javascript origin spoofing, content-generated event vulnerabilities and a possible exploitable crash in InstallVersion.compareTo.

Some of those bugs are "high risk" and could allow a malicious code writer to overtake a PC or expose a user's data. The Mozilla community's bug bounty program helped uncover some of the security holes. The bug finders each received US$500 and a Mozilla T-shirt.

How Vulnerable Are Users?

Michael Sutton, director of iDefense Labs, the company's vulnerability research arm, told LinuxInsider that the vulnerabilities were low- to mid-level critical. Of the 12 bugs, he said public exploit code is available for three of them. The availability of public exploit code increases user risk.

"There are three categories that all the exploits fall into," Sutton said. "One category includes issues like frame origin or cross-domain content injection. Those are the vulnerabilities that assist in phishing attacks. About half of the Firefox vulnerabilities fell into that category, at least one for which there was some public exploit code available."

Firefox also issued patches for denial of service attacks. However, analysts called these flaws less critical since the result of the attack is merely a browser crash.

The most serious issues were related to code or script execution. These flaws actually provide an avenue for malicious code writers to launch code on a user's machine when they visit a trusted Web site. Sutton said public code is also available for some of those vulnerabilities.

Firefox's Patch Tuesday

Firefox released its patches on infamous Patch Tuesday, Microsoft's (Nasdaq: MSFT) scheduled patch distribution day. The question, then, becomes which browser maker is more efficient in developing and distributing patches.

Microsoft's and Mozilla's approaches to distributing patches are about as different as their software development strategies. Microsoft's approach stores up patches to release once a month. Mozilla's approach is to release patches as quickly as possible.

Analysts said there are advantages and drawbacks to both strategies.

"Sometimes corporations are more comfortable with Microsoft's approach because they always know when patches are coming out and they can be prepared," Sutton said. "The downside to it is if there is a patch available on day one and the company is not releasing a patch until day 30 of the monthly cycle, then there's a long window of opportunity for something to go wrong."

With the latest Firefox update completed, Mozilla plans to release a new version of its Thunderbird e-mail client later this week. The organization also plans to release Firefox 1.1 in August or September, which will allow users to download the fixes.


Print Version E-Mail Article Reprints More by Jennifer LeClaire


More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network