Firefox plans bug fix release for next week Print
Written by Daniel   
Saturday, 24 November 2007 10:59
AddThis Social Bookmark Button
 Mozilla will release a bug fix for its Firefox browser that repairs a long-standing security flaw that can be used to launch a cross-site scripting attack

By Robert McMillan, IDG News Service
November 21, 2007
InfoWorld

Mozilla plans to release a bug fix for its Firefox browser next week, repairing a long-standing security flaw in the software.The 2.0.0.10 update is in testing right now and should be released to the public next week, following the Thanksgiving holiday in the U.S. "We are giving it a couple of days to make sure that there are no issues found and we'll release it after Thanksgiving," said Mike Schroepfer, Mozilla's vice president of engineering. Mozilla is calling on the Firefox community to test the browser during a quality assurance "testday" this Friday.

The issue was first reported last February by Jesse Ruderman, but it gained widespread attention earlier this month when researcher Petko Petkov pointed out on his blog that the flaw could be used to launch a cross-site scripting attack against the Firefox browser.

The flaw has to do with the fact that Firefox does not properly check files that are compressed using the .jar (Java Archive) format. Attackers could sneak malicious code into the Jar-compressed documents, which would then be run by the victim.... More     Comment in the Forums