On CBS MoneyWatch: 6 things NOT to do on Twitter, Facebook
BNET Business Network:
BNET
TechRepublic
ZDNet

July 31st, 2007

10 days from report to patch for new Firefox exploit

Posted by Ed Burnette @ 12:19 am

Categories: General, Scripting, Web Browsers

Tags: Mozilla Firefox, Microsoft Internet Explorer, Protocol Handler, Ed Burnette

Looks like the protocol handler problems just won’t die. On July 20th, Jesper Johansson reported that Firefox 2.0.0.5 didn’t quite get all the bugs out of passing strings to external programs registered as protocol handlers. 10 days later, Mozilla has released a patch in version 2.0.0.6. The first version of the patch was actually coded on July 21st, finalized on the 23rd, tested and reviewed, and released to auto-updates on the 30th. You can see all the gory details in bug 389106 .

Ironically, FF appears to have been doing the same thing that IE was doing, which Window Snyder called a “critical vulnerability in IE” on the 18th. Snyder gave Microsoft a hard time because they were not planning a fix, but on the 23rd he she had to eat crow, saying:

We thought this was just a problem with IE. It turns out, it is a problem with Firefox as well. We should have caught this scenario when we fixed the related problem in 2.0.0.5. We believe that defense in depth is the best way to protect people, so we’re investigating it now.

(By the way, the problem is still unpatched in Internet Explorer - see comments in the IE blog.)

I’ll bet most people never heard of protocol handlers before July so don’t be surprised if more issues are discovered around this mostly-forgotten feature now that people are looking at it (like this one). If not carefully implemented, protocol handlers can be a potential attack vector on any browser and OS, not just FF and IE on Windows. Sigh.

Ed BurnetteEd Burnette is a professional developer and author of several articles and books about computing including Hello, Android: Introducing Google's Mobile Development Platform, 2nd Edition. For disclosure of Ed's industry affiliations, click here or to view his full profile click here.

Email Ed Burnette

Subscribe to Dev Connection via Email alerts or RSS.

  • Talkback
  • Most Recent of 13 Talkback(s)
Having looked at the IE blog...
... I see that the MS people are still in denial. It is baffling to see how corporate policy produces so much horsesh*t, it basically goes like this

"Firefox has escaped their URLs please do th... (Read the rest)
Posted by: bportlock Posted on: 08/01/07 You are currently: a Guest | | Terms of Use
this is actually a Windows issue ..  bksgs1 | 07/31/07
Maybe the %00 one, but in general...  Ed BurnetteZDNet Moderator | 07/31/07
Quoting is not an issue in UNIX  Resuna | 07/31/07
Wrong  ejhonda | 07/31/07
They may have had to eat crow...  dragosani | 07/31/07
Response time  Ed BurnetteZDNet Moderator | 07/31/07
Ed, Window Snyder is...  BFD | 07/31/07
Fixed, sorry  Ed BurnetteZDNet Moderator | 07/31/07
unregister uri?  clareJ | 07/31/07
Unregistering  Ed BurnetteZDNet Moderator | 07/31/07
A prophecy which alas will prove all too true :  mhenriday | 07/31/07
This is an OS issue, not limited to Windows.  Resuna | 07/31/07
Having looked at the IE blog...  bportlock | 08/01/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More