Original URL: http://www.theregister.co.uk/2005/12/12/firefox_history_file_bug/
Mozilla has warned of a flaw in the latest version of its open source web browser software, Firefox 1.5. The security bug is liable to cause a browser to freeze (http://isc.sans.org/diary.php?date=2005-12-09) up under certain conditions but all indications are that it fails to expose systems to more invasive hacker attacks. The medium to low risk vulnerability is the first to affect Firefox 1.5 and comes days after the release of the much heralded update.
The flaw stems from errors in processing history information. That means a surfer who strays onto a maliciously constructed website may get a Firefox history file filed with junk. After this Firefox will crash every time the browser is started up until a user removes the "history.dat" file. The weakness has been confirmed in Firefox version 1.5. Advice from Mozilla on dealing with the issue can be found here (http://www.mozilla.org/security/history-title.html).
Users may want to configure Firefox to clear history information when closing the browser. This workaround, which isn't ideal because it affects functionality, is explained in an advisory by Secunia here (http://secunia.com/advisories/17934). ®
Firefox users need to update (again) (27 July 2006)
http://www.theregister.co.uk/2006/07/27/firefox_security_update/
Firefox vuln fails to imperil World Cup (5 June 2006)
http://www.theregister.co.uk/2006/06/05/firefox_vuln/
Mozilla Firefox 1.5 has landed (30 November 2005)
http://www.theregister.co.uk/2005/11/30/firefox_upgrade/
Mozilla suffers growing pains (22 September 2005)
http://www.theregister.co.uk/2005/09/22/mozilla_growing_pains/
Exploit for unpatched IE vuln fuels hacker fears (19 August 2005)
http://www.theregister.co.uk/2005/08/19/0day_ie_exploit_fears/
Firefox exploit targets zero day vulns (9 May 2005)
http://www.theregister.co.uk/2005/05/09/firefox_0day_exploit/
Browser bugs sprout eternal (6 April 2005)
http://www.theregister.co.uk/2005/04/06/browser_bugfest/
© Copyright 2008