09 May 2005
A French security testing company has found two holes in the latest version of Firefox that it rates as 'critical'.
The vulnerabilities could allow hackers to implant code in a web page that would create a batch/exe file with a malicious payload such as a Trojan or key-logger on the PC of anyone viewing the site, warned testers at the French Security Incident Response Team (FrSIRT).
"The Mozilla Foundation partially patched this issue on the server side by adding random letters and numbers to the install function, which will prevent this exploit from working," said FrSIRT, which posted the alert on Saturday.
FrSIRT rates the flaws as critical and has posted proof-of-concept exploit code on its website.
The Mozilla Foundation said in a statement: "Mozilla is aggressively working to provide a more comprehensive solution to these potential vulnerabilities and will provide that solution in a forthcoming security update.
"Users can further protect themselves today by temporarily disabling JavaScript or disabling the 'Allow websites to install software' option in Tools > Options > Web Features."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Order Processing Specialist - 12 Month Fixed Term Contract...
Great opening with one of the worlds leading information...
JAVA J2EE Developer required with RIA, web services...
Hi, Job Title : Linux Admin Location : Brussels...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?