ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Firefox flaw may not be fixable

Open source browser may need a ground up rewrite if hackers are to be believed

By Iain Thomson, 2 Oct 2006 at 16:01

A presentation at the ToorCon hacking convention in San Diego has claimed that Firefox will need key sections of code rewritten to deal with security flaws.

Coders Mischa Spiegelmock and Andrew Wbeelsoi claim that the browser's handling of Javascript is deeply flawed and will not be fixable with patches alone. The pair claimed that whatever the operating system the flaws could be used to induce a crash and allow remote execution of code on the target computer.

Window Snyder, Mozilla's security chief, said that it looked like a variation on an old attack but that the organisation was checking it out. She also criticised the pair for releasing information about the flaw before a patch or any mitigation was available.

The two also claimed they had discovered around 30 additional flaws in Firefox, but did not disclose them.

Email to a friend

Print this page

< Previous   Networking : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement