What's new
TerraForums Venus Flytrap, Nepenthes, Drosera and more talk

Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

More flaws in mozilla

Here is (One of, not the one with the code ITSELF,) the quote that a few people asked me for earlyer...

[b said:
Quote[/b] (More flaws in Mozilla Netscape @ http://informationsecurity.techtarget.com/magQual1/1,294625,sid42,00.html?Offer=SEint94 )]
Mozilla users are advised to visit Http://www.Mozilla.org and download the latest version of the browser to fix a vulnerability an attacker could use to execute arbitrary code. Reston, Va.-based antivirus firm iDefense said in an advisory that improper input validation to the SOAPParameter object constructor in Netscape and Mozilla allows execution of arbitrary code. "The SOAPParameter object's constructor contains an integer overflow which allows controllable heap corruption," the advisory said. "A Web page could be constructed to leverage this into remote execution of arbitrary code." Netscape 7.0 and 7.1 have been confirmed to be vulnerable. Mozilla 1.6 is also vulnerable, and iDefense suspects earlier versions of both browsers may also be vulnerable. "Netscape 7.1 is the latest version of Netscape available. Netscape has not released any information indicating they are intending to release future versions of the Netscape browser, and no longer have any developers working on this project," the advisory said. The latest release of the Mozilla browser is not affected by this vulnerability. The company said users could also disable Javascript in the browser as a workaround.

Told ya the old Mozilla DID have flaws
smile.gif
(Yes, I DID mix Gozilla up with Mozilla, but I DID remember using the old browser (But again, mixed it up with Gozilla) and having problems... and someone questioned me about it in the topic... So here ya go
smile.gif
Posted this to clear up some earlier confusion
 
No one said Mozilla did not have a flaws. You said it had spyware, which was incorrect and you apologized for saying so.

There is a flaw in the new versions of Mozilla (and derivatives). No way to tell if that's what you're talking about since you posted a link to a site that requires subsriptions. There is already a patch out to fix this problem. If you'd like to read interesting articles about browser security, how about this one:
"The U.S. government's Computer Emergency Readiness Team (US-CERT) is warning Web surfers to stop using Microsoft's Internet Explorer (IE) browser."
 
Doh... Well not in a post, but I did to someone in a PM
smilie4.gif


Ok I'm lost now
confused.gif


I'll take a look at that warning about IE site... But I didn't say anything about it not having flaws or spyware...
 
Why are you attacking Mozilla all the time? The makers deserve support! In IE most vulnerabilities are well known until they get patched months later. There are still several known security holes in IE every hacker could use to run code on your machine. If the Mozilla Foundation gets to know a bug in their code they fix it at once and warn everyone. And thats the difference which really counts. Microsoft uses the old "security through obscurity" method which cannot work if there are people outside in the web who know the attack points.

Because of that the CERTs of the USA, most European countries and more countries througout the world say that it is a good idea to leave IE behind and change to Mozilla or Opera.

BTW: No software product in that complexity can be flawless! Some are coded in a safer way, some have bigger holes (IE). But the important thing is the way to deal with those security risks.

Jan

P.S. Opera is not open source but very good, too. Mozilla is a bit more secure because everyone can check the sources.
 
I do not feel like arguing right now, i am just posting somethign SOMEONE ASKED ME FOR. right now, i could blow through the roof on other... matters... so ill dismiss this, for now.
 
Back
Top