The Register® — Biting the hand that feeds IT

Small security bug in Firefox, users unscathed

History repeating

Free whitepaper – Vulnerability management buyer's checklist

Mozilla has warned of a flaw in the latest version of its open source web browser software, Firefox 1.5. The security bug is liable to cause a browser to freeze up under certain conditions but all indications are that it fails to expose systems to more invasive hacker attacks. The medium to low risk vulnerability is the first to affect Firefox 1.5 and comes days after the release of the much heralded update.

The flaw stems from errors in processing history information. That means a surfer who strays onto a maliciously constructed website may get a Firefox history file filed with junk. After this Firefox will crash every time the browser is started up until a user removes the "history.dat" file. The weakness has been confirmed in Firefox version 1.5. Advice from Mozilla on dealing with the issue can be found here.

Users may want to configure Firefox to clear history information when closing the browser. This workaround, which isn't ideal because it affects functionality, is explained in an advisory by Secunia here. ®

Free whitepaper – The starter PKI program

Don’t Miss

HandcuffsFeds: Hospital hacker's 'massive' DDoS averted

Arrest foils 'Devil's Day' scheme

thumbs down teaser 75Buggy 'smart meters' open door to power-grid botnet

Grid-burrowing worm only the beginning

MicrosoftMicrosoft knew of nasty IE bug a year before attacks

Security delayed or security denied?

BlockMaster SafeStickBlockMaster SafeStick hardware-encrypted USB drive

Review Tough enough?