Microsoft, Mozilla look into browser flaws

By Joris Evers on 19 February 2007

Tags: browser | firefox | ie7 | microsoft | mozilla | open source | security | wrote | flaw | attack

Microsoft and Mozilla are each working to tackle recently disclosed security flaws in the Internet Explorer and Firefox Web browsers.

The vulnerabilities were described last week in postings to a popular security mailing list by researcher Michal Zalewski. Each browser could enable miscreants to grab data via malicious Web sites, Zalewski said.

In addition, another Firefox flaw could let attackers change cookie files on the user's PC, he said.

In the case of Internet Explorer, the problem affects the latest version, IE 7, and probably earlier releases, Zalewski wrote. Microsoft confirmed that the flaw could open up files stored on a PC's hard drive to an attacker, but only if the location of a given file is already known.

"In order to be successful, an attacker in advance would have to convince the user to enter the location of a file into an attacker's Web page through social engineering," a Microsoft representative said in an e-mail statement Friday. The software giant is still investigating the issue and will take "appropriate action," the representative said.

Flaws in Firefox
Firefox is affected by two security holes, both described by Zalewski. One is similar to the Internet Explorer problem, while the other could let miscreants change cookie files stored on a PC running the vulnerable browser. Cookies are small files stored on a PC by Web sites, to remember login credentials and site preferences, for example.

"The impact is quite severe," Zalewski wrote, regarding the cookie problem, in a posting to the Full Disclosure mailing list on Wednesday. Because cookies can be changed by a malicious Web site, an attacker can change the way other sites are displayed or how they work, he wrote.

Firefox developers, coordinated by Mozilla, have already crafted a fix for this flaw, according to a bug entry on the organisation's Web site. The patch has not yet been made available to the browser's users. Mozilla typically releases updates with a number of fixes, and the next patch release could come soon, according to the site posting. The bugs affect the latest versions of the open-source browser, Zalewski wrote.

"The proposed fix seems to be OK and was provided swiftly," Zalewski wrote in an e-mail interview Friday. Last week, two other information-disclosure bugs in Firefox were publicised.

Meanwhile, smart Internet users should be aware of the Web sites they visit. Firefox users can also install the "NoScript" add-on to prevent script code from running on Web sites. This blocks Zalewski's proof-of-concept exploit for the information disclosure bug and will also prevent many other attacks.

Like this article? Click below to send it to your mobile for free!

Be the first to comment on this article!

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • Internet Explorer 8 Beta 2

  • Internet allowed in Sydney school exam

  • SMS updates gone for Aussie twitterers

  • Twitter targeted by malware attacks

  • Google defends Street View coverage

  • Google Street View now in Australia

  • PayPal to reimburse Aussie eBayers

  • 3 Australia doubles down on data

  • Apple's MobileMe woes continue

More articles »

Find the right software

Brand
  • Multiple options can be selected

    The Explain Series

    • Internet Explorer 8 Beta 2

      Internet Explorer 8 Beta 2

      Microsoft's release should retain its browser base but doesn't yet have enough to lure loyal Firefox users back to Internet Explorer.

    • MobileMe

      MobileMe

      MobileMe is the successor to .Mac, Apple's subscription service for publishing photos and other personal content to the Web.

    • Firefox 3

      Firefox 3

      If only for the speed, lightness of being and security alone, Firefox remains our Editors' Choice for best internet browser.

    • Opera 9.5

      Opera 9.5

      Long considered a cult favourite, Opera 9.5 for Windows and Mac has introduced some compelling improvements to security, speed and synchronisation — yes, syncing in a browser!— is there enough here to make you a convert?

    • Nokia Music Store

      Nokia Music Store

      If you can access the Nokia Music Store then we think it's worth a look; but Nokia isn't making it easy.

    More reviews »

    Membership benefits

    Create wishlists

    Create wishlists

    See a product on CNET.com.au that you want? Add it to your wishlist and send a hint to your friends and family. Sign up for a free CNET.com.au membership now!