Mozilla warns of security holes, updates Firefox
Users urged to upgrade to avoid possible attacks
News Story by Joris Evers
FEBRUARY 26, 2005 <NOBR>
(IDG NEWS SERVICE) - </NOBR>Several security vulnerabilities in Firefox and the Mozilla Suite of Internet software put users of the open-source products at risk of hacker attacks, The Mozilla Foundation warned this week.
The organization released
Firefox 1.0.1, which fixes 17 security flaws in the popular Web browser. The most serious flaws could allow an attacker to gain full control over a victim's PC, The Mozilla Foundation said in a
statement. Firefox 1.0 was released in November and has since been downloaded more than 27 million times.
....
For protection against possible exploitation of the security flaws, users should download and install the latest version of Firefox, The Mozilla Foundation said. The organization doesn't offer patches to fix the problems without having to install a new browser.
Most of these flaws also affect the Mozilla Suite, which includes a Web browser, an e-mail client, an Internet Relay Chat client and a Web page editor. However, users of the suite are left vulnerable because no fixes are yet available. Mozilla 1.7.6, the update that fixes the issues, is due out in "a couple of weeks," according to a Mozilla Foundation spokesman. The public warning of the security vulnerabilities is evidence that The Mozilla Foundation's products give a false sense of security, charged Thor Larholm, a researcher with
PivX Solutions Inc., a Newport Beach, Calif.-based company that specializes in security for Windows-based systems. "We have to remember that all software has security vulnerabilities, the only difference is in how we anticipate them and inform the world about their existence," he said via e-mail.
<!--STOPINDEX-->