Get custom programming done at GetAFreelancer.com!
Showing posts with label Browser. Show all posts
Showing posts with label Browser. Show all posts

Friday, December 19, 2008

Microsoft rushes out quick fix for IE7

Microsoft is rushing out patch to fix problematic security issues with its Internet Explorer 7 browser.The security update, marked as 'critical', will be available from 6pm on 17 December.Problems due to the security flaw have affected as many as 10,000 websites, allowing cyber-criminals to take control of people's computers and steal passwords and private data.

Criminality inevitable

According to Rick Ferguson, a senior security adviser at security firm Trend Micro, told the BBC: "It is inevitable that it will be adapted by criminals. It's just a question of modifying the payload the trojan installs."

The BBC report adds that: "It is relatively unusual for Microsoft to issue what it calls an "out-of-band" security bulletin and experts are reading the decision to rush out a patch as evidence of the potential danger of the flaw."

While some security experts have suggested temporarily swopping over to alternative browsers such as Firefox, Opera, Chrome or Apple's Safari, Graham Cluley, senior consultant with security firm Sophos, reminded the BBC that:

"Firefox has issued patches and Apple has too. Whichever browser you are using you have to keep it up to date… People have to be prepared and willing to install security updates. That nagging screen asking if you want to update should not be ignored."

Firefox Issues Eight Patches for Web Browser


Mozilla has issued eight patches for its Firefox Web browser, three of which fix problems classified as critical.

The patches come after security experts have recommended using a browser other than Microsoft's Internet Explorer 7 and older versions of IE due to a dangerous vulnerability. Microsoft is due to release an emergency patch for that problem Wednesday.

Two of the critical Firefox problems could allow an attacker execute a cross-site scripting attack, in which scripts or commands from one Web application that shouldn't run in another are successfully executed. The third problem relates to Firefox's browser engine, and could make it crash or possibly allow someone to remotely execute code on a PC, Mozilla said in its advisory.

Mozilla defines a critical vulnerability as one that could allow an attacker to run code on a machine in the course of normal Web browsing.

The patches are for Firefox version numbers 3.04 and 2.0.0.18. Mozilla has said this round of patches will be the last for Firefox 2, which it will now stop supporting. The update also removes the phishing filter in Firefox 2 because the browser uses an outdated version of a protocol used to import a blocklist of phishing sites supplied by Google. Firefox 2 users are being promoted to upgrade to Firefox 3.

Firefox's auto-update mechanism should automatically download these latest patches, and users will be prompted to restart the browser to complete the process.