IT DRILLDOWN
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Public Teleconferences
Join CIO Executive Council members and participate in the following live teleconferences:

* Planning for Succession:
Models for IT Leadership Development, June 23
* Change Leadership at General Growth Properties: A
Pathways Leadership Development Seminar, June 25
* Managing Change: Centralizing Your IT Organization
July 29

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
BONUS LINKS
 
Database Security
Sentrigo is the leader in database security, auditing and protection.
 
 

Firefox's Serious Bug to Be Patched Next Week

Mozilla plans to patch a serious problem in its Firefox browser next week.

 

November 21, 2007 — IDG News Service (San Francisco Bureau) — Mozilla plans to release a bug-fix for its Firefox browser next week, repairing a long-standing security flaw in the software.

The 2.0.0.10 update is in testing now and should be released to the public next week, following the Thanksgiving holiday in the United States. "We are giving it a couple of days to make sure that there are no issues found and we'll release it after Thanksgiving," said Mike Schroepfer, Mozilla's vice president of engineering.

Mozilla is calling on the Firefox community to test the browser during a quality assurance "testday" this Friday.

The issue was first reported last February by Jesse Ruderman, but it gained widespread attention earlier this month when researcher Petko Petkov pointed out on his blog that the flaw could be used to launch a cross-site scripting attack against the Firefox browser.

The flaw has to do with the fact that Firefox does not properly check files that are compressed using the .jar (Java Archive) format. Attackers could sneak malicious code into the Jar-compressed documents, which would then be run by the victim.

A few days after Petkov posted his findings, a researcher going by the name "Bedford" showed how this attack could be launched against Google users, giving them access to victims' Gmail accounts, Google searches and other sensitive data stored on the Google Web site.

"This means that attackers can get to any place on Google and do whatever they want with your profile and your online presence," Petkov wrote in a blog posting.

Though both Petkov's and Bedford's vulnerabilities are related to the way Firefox handles .jar files, Mozilla considers them to be two separate issues, both of which are set to be patched in next week's 2.0.0.10 release.

Other stories by Robert McMillan

Copyright 2006 IDG News Service, International Data Group Inc. All rights reserved.
Loading...
 
 
CENTER OF EXCELLENCE
 
Security
» New 2008 Report: Outbound Email and Data Loss Prevention in Today's Enterprise
Read the statistics about how large companies manage the risks associated with outbound email, blog postings, media sharing sites, mobile Internet-connected devices and more.
» Regulations Shift Focus on Outbound Email Security
Find out more about the impact of data protection regulations and standards such as HIPAA, PCI, and PIIG, which place new constraints on data.
» Messaging Security Goes Virtual
Learn how virtual appliances can eliminate "appliance overload" by combining the advantages of hardware appliances and virtualization technology.
» Encryption Made Easy: The Advantages of Identity Based Encryption
Find out why email encyrption is critical to an organization's overall security architecture and the advantages of identity-based encryption over traditional approaches.
» The Great Email Security Debate: Appliances, SaaS, or Virtual?
Hear how you can keep your messaging infrastructure safe from spam and viruses, or prevent leaks of your organization's most valuable data.
Center sponsored by

 
 
ABCs
 

Just the basics, please. Sometimes we all need a refresher or we need to make sure our team and our colleagues are all on the same page.

Over 25 tutorials on everything from business intelligence to virtualization.

 
 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Building an Online Customer Experience Competency

They Cant Steal What You Don't Have: Smart Security Choices for Mobile Workers

The Great Email Security Debate: Appliances, SaaS, or Virtual?

Messaging Security Goes Virtual

Outbound Email and Data Loss Prevention in Today's Enterprise

How to Manage the Mobile Work Environment

How to simplify mobility and reduce the cost of supporting mobile workers

Rethinking the Corporate Help Desk: Learn how to deliver anywhere, anytime incident response

Cisco IT eSummit: View 30-minute webinars, technical demos and case studies

Technologies of ETERNUS VS900 Storage Virtualization Switch

New research validates telepresence solutions.

Configuration Assessment: Choosing the Right Solution

How to Calculate the ROI of Remote Support

31 Best Practices for the Service Desk

Webcast: Building an Optimized Infrastructure

Juniper Networks is changing the economics of networking with a no-compromise, highperformance and service-oriented approach

Research about the efficiencies created by different operating systems.

Unified Communications Software: The Death of VoIP?

HP and Oracle deploy unbreakable computing infrastructure at Replacements, Ltd.

Seeing is Believing: The Value of Video Collaboration

Getting Network Management Right: A Gartner IT briefing

Oracle Database 11g: Real Application Testing & Manageability

Sheriff's Office Uses PocketCop to Access Police Databases from BlackBerry® Smartphones

The BlackBerry Solution Adds Significant Benefit to Toshiba

The New Foundation of Storage: Xiotech's Intelligent Storage Element

Best Practices for Providing Secure and Cost-Effective Remote Access

How to Offer the Strongest SSL Encryption

The Advantages of Identity Based Encryption

Regulations Shift Focus on Outbound Email Security

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Get Control of Mobile Data (and More)

Mitigating Risk with Security Assessments

Webcast: Best practices in application security: How do you stack up?

Using Oracle Database 10g Automatic Storage Management with Fujitsu Storage

High-Speed Backups without Stopping Business Applications

Optimizing Infrastructure Control

Effective Security with a Continuous Approach to ISO 27001 Compliance

How Does Your IT Help Desk Measure Up?

Webcast: Achieving business alignment and agility with the right capabilities framework

White Paper: Juniper Networks Ethernet Switching Solutions Reduce Operational IT Expenses

Webcast: Learn why companies must invest in an agile network infrastructure

White Paper: Businesses Thrive by Unifying Business Communications

Efficient by design: Watch this flash demo of the Quad-Core AMD Opteron Processor

Renowned Engineering Institution Chooses AMD Processor-Based Servers

High-Definition: The Evolution of Video Conferencing

Unify and Conquer: The Benefits of Unified Communications.

Key challenges facing today's IT service and support

Heinz Uses a Wireless, Automated, Auditing process on BlackBerry® devices

Webcast: Solutions to the Toughest IT Challenges in Remote Offices

Extending PCI Compliance to the Mobile Workforce