Mozilla releases Firefox security update

By Dawn Kawamoto, CNET News.com
Friday, May 13, 2005 10:49 AM

update A security update for the Firefox open-source browser has been released by the Mozilla Foundation, a move that follows the public disclosure of exploit code for two "extremely critical" vulnerabilities.

Mozilla's Firefox 1.0.4, released Wednesday, addresses vulnerabilities that surfaced earlier this week. The update includes several security fixes, as well as a fix to DHTML errors that were encountered on some Web sites, according to a posting on Mozilla's Web site.

The update is designed to address the two flaws, which when combined could allow malicious attackers to engage in cross-site scripting and remote system access. Although the two vulnerabilities could be exploited, there were no known active exploits.

Security monitoring company Secunia had rated the flaws as "extremely critical."

The update means that people can safely install extensions from non-Mozilla sites, whereas before they were at risk because of the vulnerabilities, said Chris Hofmann, director of engineering for Mozilla.

Currently, Mozilla has the update out in 12 languages and anticipates sending it out in another 24 languages in the coming days, Hofmann said.

Since the debut of Firefox 1.0 in November, the browser has grown at a rapid pace, passing the 50 million download mark last month.

With its initial release last fall, the open-source browser has demonstrated to analysts that the mature Web browser market dominated by Microsoft's Internet Explorer can be shaken up. Microsoft's IE has begun to see its market share dip slightly--a first in a number of years.

Firefox held 6.8 percent of the domestic market share as of late April, while Microsoft saw its role dip to 88.9 percent, compared with more than 90 percent share last year.

The fast-paced growth of Firefox, however, is beginning to show signs of slowing, according to results released this week by WebSideStory.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Save changes to all open Word documents at one time

Microsoft Office Suite

If your Word sessions often wind up with a lot of open documents, this obscure command can streamline the process of closing them and saving your changes.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web