By Kimberly Hill LinuxInsider Part of the ECT News Network
07/19/07 11:16 AM PT
Firefox users can now download a new version of the program released by Mozilla that fixes a security hole spotted last week. The problem was putting computers loaded with Firefox and Microsoft's Internet Explorer at risk. The patch prevents Firefox from accepting bad data from Explorer.
Mozilla, maker of open source Web browser application Firefox, released a new version of the program that fixes a security issue stemming from an interaction between Microsoft's (Nasdaq: MSFT) Internet Explorer (IE) and Firefox. Version 2.0.0.5 of Firefox was made available for download on Wednesday.
The problem -- first reported by security firm Secunia -- arises on computers that have both IE and Firefox installed. When a user browses Web sites using IE, malicious code can be sent to Firefox and, notably, other programs on the user's computer.
Mozilla, in its security blog, called on Microsoft to patch the hole on the IE side. For its part, though, Mozilla states that "[t]his patch for Firefox prevents Firefox from accepting bad data from Internet Explorer."
Explorer Running, Firefox Vulnerable
The problem centers on malicious Javascript code that can be sent from IE to Firefox through arbitrary command line arguments, Secunia describes. Firefox does not have to be running for the code to be transmitted, just installed on the same computer as IE. When a user clicks on links at a malicious Web site, the hole can be exploited without the user's knowledge.
Mozilla has taken pains to point out that the problem cannot occur when using Firefox to browse the Web and that it is not aware of attackers taking advantage of the vulnerability. It also notes in its security blog that "[a] similar interaction between Safari and Firefox was reported earlier and fixed by Apple."
The blog entry announcing the fix and calling on Microsoft to repair the problem from its side was authored by Window Snyder, chief security officer for Mozilla. It is the only comment that Mozilla is making publicly about the matter, Mozilla spokesperson Steve Naventi told LinuxInsider.
Not Just Firefox
Media coverage of this security concern has focused on Firefox, perhaps due to the fierce competition between the IE and Mozilla browsers. The vulnerability, though, exists in a wide range of programs that will accept executable code from IE, according to sources in the security community.
The issue has indeed been fixed from the Firefox side, but a hole remains open from the IE point of view, Danish programmer and self-described hacker Thor Larholm noted in a Wednesday blog entry.
"I can still automatically launch a wide range of external applications from Internet Explorer and provide them with arbitrary command line arguments. AcroRd32.exe (Adobe Acrobat PDF Reader), aim.exe (AOL Instant Messenger), Outlook.exe, msimn.exe (Outlook Express), netmeeting.exe, HelpCtr.exe (Windows Help Center), mirc.exe, Skype.exe, wab.exe (Windows Address Book) and wmplayer.exe (Windows Media Player) -- just to name a few," he said.
Finger-Pointing Game
Of course, having two applications involved in one security issue makes for ample finger-pointing room. The blogosphere is rife with diatribes assigning blame alternately to Microsoft and Mozilla on the problem.
The fault, though, lies with both, according to Chenxi Wang, principal analyst with Forrester Research.
"This is really a gray area," she told LinuxInsider. Microsoft should be vigilant about what IE passes on to other programs, she asserted. On the other hand, all programs -- Firefox included -- are responsible to protect themselves against potentially malicious input.
"This issue does highlight the importance of investigating your trust model and your assumptions," Wang said. "I bet the Firefox designers did not envision such an attack when they decided to allow arbitrary parameters to be passed from IE, or any other Windows application. Many security attacks happen because of misplaced assumptions, and this is one of them."
Sony BMG Takes Software Firm to Court Over Rootkit Fiasco July 13, 2007
Sony BMG is suing the Amergence Group, the company that developed a controversial copy protection software embedded in selected CDs, for $12 million in damages. The music giant wants to recoup money lost from refunds it gave to consumers who bought the problematic CDs. The software that has the "horrible rootkit solution" was not made by The Amergence Group, the company maintains.
Related Stories
Firefox Sinks Its Teeth Into Explorer in Europe July 17, 2007
Mozilla's Firefox accounted for about 28 percent of Europe's browser market in the first week of July, according to the Web analytics firm XiTi Monitor. Meanwhile, usage of Internet Explorer dropped to 66.5 percent in early July from 73 percent a year ago, the firm reported.
Surfing Fast and Loose With Safari 3 Beta July 13, 2007
A private browsing feature is included with Safari 3. With private browsing enabled, no text forms or history are recorded, which allows you to surf without fear of someone tracking where you have been. Amazingly, the back and forward navigation buttons still work until the window is closed. However, the Web browser's main attraction is the speed with which it loads Web pages.
Internet Explorer Linked to Firefox Security Hole July 11, 2007
The latest browser war dustup pits Mozilla's Firefox against Microsoft's Internet Explorer, but this time the tiff isn't about market share. It appears that IE may undermine Firefox's security when a Net surfer clicks on malicious page links using the IE browser and Firefox also happens to be installed on the machine.
Related News Alerts
More by Kimberly Hill
FCC Begins Long Climb Toward Broadband for All March 15, 2010
The FCC began unveiling its plan for achieving national access to broadband in the U.S. with an executive summary that outlines the government's role in broad strokes: promote competition; allocate resources wisely; monitor service access in all regions and among all populations; establish standards for the use of broadband in public institutions.
Apple's Remote: An App Near to My TV-Hungry Heart February 05, 2009
If you think free iPhone apps are worth the price, think again -- especially if Apple is the developer. Remote is one freebie that you're going to want to use every time you turn on your TV. And keep using for hours, even if you don't make a single phone call or surf to a single Web site. There's a method to Apple's generosity: It hopes you'll never put your iPhone down.
Boxee Gives New Meaning to Plug and Play February 04, 2009
If you're longing for media convergence but not yet sure you want to spend big bucks to make it happen in a still-shifting television landscape, Boxee might be just the app for you. MacNewsWorld reviewer Kimberly Hill, who's been testing the alpha release with her Mac, considers it a great way to wait until the dust settles.