internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Ad-Aware 2008 Free
Internet Explorer 7
QuickTime for Windows
Paint Shop Pro
Mozilla Firefox Portable Edition 3
AVG Anti-Virus Free
Windows XP Service Pack 3
Ashampoo WinOptimizer
Adobe Flash Player
Windows Live Suite

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Mozilla Patches Vulnerability
Mozilla Catches the Vulnerability Bug
Jim Wagner

Mozilla Developers at the Mozilla Foundation quickly patched a hole in its web browser that could allow crackers to take over users' PCs.

The 572-byte patch disables the browser's use of the "shell:" external protocol handler. The handler determines what application to execute when it runs across a specific file extension. One example of this is when a user clicks on an e-mail address link on a web page and the user's default e-mail client launches.

The vulnerability only affects machines running Mozilla, Mozilla Firefox, and Mozilla Thunderbird on the Windows operating system; Linux and Macintosh users aren't affected. Users can also download the latest versions of the affected applications to eliminate the flaw (Mozilla 1.7.1, Firefox 0.9.2, and Thunderbird 0.7.2).

A user first reported the vulnerability this past Wednesday on a public security mailing list called Full-Disclosure. By the end of the day, Mozilla developers confirmed the report, and then released a patch the following day. Industry experts say this turnaround time is one of open source's greatest strengths.

Mozilla, which became an open source project after AOL essentially handed over the reins to its Netscape browser, is developed and updated through the efforts of volunteers throughout the world. The Mozilla Foundation is able to accomplish what many proprietary software companies can't, with a software team numbering in the thousands that can root out potential vulnerabilities.

Take, for example, Internet Explorer and Opera, web browsers that have been hard-hit recently with software vulnerabilities. Opera was hit with breaches last November, May, and June. IE has been beset with so many new bugs that have not been fixed quickly enough that the U.S. Computer Emergency Readiness Team (US-CERT) warned web users not to use the browser.

Yankee Group Analyst Patrick Mahoney said that, in the grand software scheme of things, Microsoft's IE is well down there on the list of priorities at the company.

"Mozilla is working very hard at being a robust browser, and I think one of the reasons is because it's their sole purpose," he said. "Internet Explorer for Microsoft is an embedded, almost given, part of their operating system. I don't think they've been as responsive, because, as we all know, it's not part of their primary product line."

That doesn't mean that Microsoft isn't looking into the vulnerabilities, Mahoney said, but the slow patch releases are one of the reasons Mozilla is getting so much attention lately. He said that for the time being, casual web surfers will stick with IE. Microsoft plans to release significant security enhancements for IE in Windows XP Service Pack 2, due out later this year.

News courtesy of internetnews.com

July 12, 2004


Download Mozilla Now!Download

Download Mozilla Firefox Now!Download

Download Mozilla Thunderbird Now!Download

View All Web Browsers

Contents:
1. Mozilla Catches the Vulnerability Bug


Additional Articles:

  • Mozilla 1.0 Steps Onto the Browser Stage
  • Mozilla, Opera Join Forces for New W3C Proposal
  • Mozilla, Opera Unite to Standardize Web
  • PC Takeover Flaw in Mozilla, Netscape
  • Mozilla: Dollars for Security Bugs
  • IBM and Novell Join Mozilla for XForms
  • New Mozilla Flaws Exposed
  • Mozilla Foundation Will No Longer Release Mozilla




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Solutions
    Whitepapers and eBooks
    IBM eBook: Planning a Service Oriented Architecture
    IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
    Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
    Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
    Intel Go Parallel Article: Getting Started with TBB on Windows
    Microsoft Article: 7.0, Microsoft's Lucky Version?
    Avaya Article: How to Feed Data into the Avaya Event Processor
    IBM Article: Developing a Software Policy for Your Organization
    Microsoft Article: Managing Virtual Machines with Microsoft System Center
    Intel Go Parallel Article: Intel Threading Tools and OpenMP
    HP eBook: Storage Networking , Part 1
    Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES
    Webcasts
    HP Video: StorageWorks EVA4400 and Oracle
    HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
    Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
    MORE WEBCASTS, PODCASTS, AND VIDEOS
    Downloads and eKits
    Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
    Iron Speed Designer Application Generator
    MORE DOWNLOADS, EKITS, AND FREE TRIALS
    Tutorials and Demos
    Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
    IBM Article: Enterprise Search--Do You Know What's Out There?
    HP Demo: StorageWorks EVA4400
    Microsoft Article: The Progress and Promise of Deep Zoom
    Microsoft How-to Article: Get Going with Silverlight and Windows Live
    MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES