Browser bugs hit Firefox and IE7

 

Security researchers have warned of new vulnerabilities in Mozilla's Firefox and Microsoft's Internet Explorer.

In a posting to the Full Disclosure mailing list, security researcher Michal Zalewski outlined two vulnerabilities in each of the popular browsers. 

The vulnerabilities could allow attackers to overwrite the URL bar, or steal user data and remotely download and execute code.

A Microsoft spokesperson told www.vnunet.com that that the company is investigating two reported Internet Explorer vulnerabilities, but declined to acknowledge that they were uncovered by Zalewski.

The most serious of the Internet Explorer flaws could allow an attacker to steal cookie files, inject malicious code into web pages and steal sensitive information for IE6 and IE7, according to Zalewski.

The second vulnerability only affects IE 6 and is said to pose less of a risk. The flaw could allow an attacker to spoof Internet Explorer's URL bar, possibly allowing an attacker to disguise phishing or scam sites as a trusted website.

Zalewski said that the more important of the two Firefox vulnerabilities could allow an attacker to inject malicious JavaScript code to log keystrokes.

This vulnerability was confirmed to be a variant of a previously reported flaw on Mozilla's Bugzilla reporting service. 

The second reported vulnerability uses flaws in the way Firefox handles confirmation dialog boxes.

Zalewski claimed that the vulnerability could allow an attacker to download and execute software without the user's knowledge.

The Bugzilla page for the second reported vulnerability is currently closed to unauthorised users.

Copyright ©v3.co.uk


Browser bugs hit Firefox and IE7
 
 
 
 
 
Top Stories
Telstra shifts BigPond email to Windows Live
All data to be migrated to Microsoft cloud.
 
Windows 8: Under the hood
Part One of iTnews' enterprise guide to Windows 8.
 
iTnews on tour: The Executive Summit Series
Join us in Sydney and Melbourne to meet Australia's tech leaders.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Would you be concerned about your business' email data being hosted offshore?

   |   View results
Yes
  89%
 
No
  11%
TOTAL VOTES: 90

Vote