Mozilla, Opera Plug Security Holes

The browser makers release new versions of their software to fix a series of vulnerabilities, as Mozilla readies a new patch system for Firefox.

The Mozilla Foundation and Opera Software ASA have released updates to their Web browsers to fix a series of security vulnerabilities.

Mozilla on Wednesday posted new versions of its Firefox browser, Thunderbird e-mail client and Mozilla suite that provide fixes to three issues. They include a newly reported critical vulnerability affecting multiple vendors software that uses the library for the Portable Networks Graphic (PNG) image format.

The other two issues, as previously reported, were related to the handling of security certificates in the Mozilla browsers that, among other things, could allow an attacker to lull users into a false sense of security on a site.

Mozilla had said last week that fixes were forthcoming and decided to incorporate them in new versions of its browsers, said Chris Hofmann, the open-source groups director of engineering. The new versions are Mozilla 1.7.2, Firefox 0.9.3 and Thunderbird 0.7.3.

Separately this week, Opera released a new version of its browser, Opera 7.54, to fix a set of security issues. They included a critical vulnerability reported in an advisory from GreyMagic Software that could allow an attacker to gain read-access to a users files and folders as well as to track browsing history and steal cookies.

According to its version notes, Opera also fixed a reported spoofing issue that could allow page content to be loaded without the site URL changing, along with another URL vulnerability.


For insights on security coverage around the Web, check out Security Center Editor Larry Seltzers Weblog.

Mozilla and Opera make the two most popular alternative browsers to Microsoft Corp.s Internet Explorer, which also has been plagued by security vulnerabilities. Mozillas Gecko rendering engine and code also serve as the underpinnings for the Netscape browser.

For its part, Mozilla is planning to add a new security patch mechanism into its Firefox browser, Hofmann said. Firefox, still in technology preview releases, is expected to reach a full version release this year.

For version 1.0, Mozilla is working on an automated process where users would be prompted when new security fixes are available and be able to instantly update browser components, Hofmann said.

Also earlier in the week, Mozilla launched a bounty program to entice its users and developers to discover and report security vulnerabilities.

Through its Security Bug Bounty Program, the Mountain View, Calif., foundation is offering $500 cash to users who report significant security bugs in Mozilla software. Linux vendor Linspire Inc. and Internet entrepreneur Mark Shuttleworth are funding the program.


Check out eWEEK.coms Security Center at for the latest security news, reviews and analysis.


Be sure to add our security news feed to your RSS newsreader or My Yahoo page