Feeds

Mozilla disables IDN to guard against Firefox flaw

The fix is in

Intelligent flash storage arrays

Mozilla developers have acted quickly to release a workaround for Firefox hours after the public disclosure of a potentially serious security vulnerability in the browser software on Friday (9 September). The security flaw stems from a bug used in code to parse certain URLs which might be used to crash vulnerable systems or, at least in theory, load malicious code if surfers using Firefox are induced into visiting maliciously-constructed websites.

The vulnerability affects all versions of Mozilla Firefox and the Mozilla Suite, according to the Mozilla Fundation. It has issued a workaround designed to guard against malicious exploitation pending the release of a more comprehensive fix. "This basically disables the vulnerability and gives Mozilla developers more time to develop a patch to address the problem and return the the feature to full functionality," a Mozilla spokeswoman explained.

The workaround involves a configuration change which, as a temporary measure, disables IDN (International Domain Name) in the browser. IDN functionality will be restored in a future product update. The fix can be made either as a manual configuration change or a tiny "patch" which makes the necessary configuration changes for the user.

Although there are no known exploits for the vulnerability, "proof of concept" code has been published and fans of the alternative browser are strongly urged to apply the Mozilla Fundation's workaround. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.
Mitigating web security risk with SSL certificates
Web-based systems are essential tools for running business processes and delivering services to customers.