Google fixes 'minor' Gmail flaw

By Joris Evers, CNET News.com
Friday, March 03, 2006 10:55 AM

Google has fixed a flaw in its Gmail Web based e-mail service after the problem was disclosed by a blogger, the company said Thursday.

The flaw could allow JavaScript code to run when viewing a message in Gmail, potentially allowing malicious code to be used by an attacker to compromise a Gmail account, according to a blogger who calls himself "Anthony."

The blogger, who claims to be a 14-year-old student, found the flaw when sending code from his Yahoo Web mail account to his Gmail account, he wrote on Wednesday. The Web log is hosted by Google's Blogger service.

Google fixed the flaw "very shortly after the initial blog post went up," a representative for the Mountain View, Calif., company said. "We learned of a minor security flaw in Gmail a little while ago and worked quickly to fix the problem, which has now been resolved," the representative said.

Because the vulnerability was fixed quickly, it likely never was exploited in any attacks, the representative said. Still, Google would have preferred to have been alerted to the flaw privately, instead of via a public blog.

"We encourage all vulnerability reporters to follow responsible disclosure practices and notify vendors first before making the vulnerability public," the representative said.

Flaws in online services are found regularly. Last December, Google fixed a security hole in the mechanism it uses to generate error pages for forbidden redirects and pages that don't exist on the Google Web site. The flaw opened the door to phishing scams, account hijacks and other attacks.

Similar flaws have been discovered and fixed in other parts of Google's Web site, as well as in Microsoft's Xbox 360 Web site and Yahoo's Web-based e-mail service.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

How to recession-proof IT

Tech Management

In the current economic environment, IT is well positioned to make a compelling case for strategic spending that can help weather the storm.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apps
  2. attack
  3. attacks
  4. bank
  5. card
  6. chrome
  7. cisco
  8. data
  9. details
  10. facebook
  11. fix
  12. flaw
  13. flaws
  14. google
  15. hack
  16. issues
  17. makes
  18. malware
  19. mcafee
  20. microsoft
  21. patches
  22. privacy
  23. researchers
  24. risk
  25. security
  26. symantec
  27. uk
  28. updates
  29. us
  30. vmware

No-holds barred on netbooks

Blog thumbnail

The journalist group that I belong to, CyberPress, held our regular industry forum last Friday and I should say that it was the best that we've ever had since we..... by Melvin G. Calimag

Read more »