Mozilla Releases Fix for IDN Bug and Other Flaws
MOUNTAIN VIEW, CA – In response to recently revealed security flaws, the Mozilla Foundation has released Firefox 1.0.7, a new version of the browser which contains fixes for two critical vulnerabilities.Released Wednesday morning, the new version of Firefox addresses a problem with the way the browser handles International Domain Names (IDN), URLs that use international characters and not the Latin alphabet. Security researcher Tom Ferris originally reported the flaw, which he said could be exploited to allow for an attacker to execute code on an affected host remotely.
According to Mozilla head of products Chris Beard, version 1.0.7 also fixed a critical flaw in the way the software handles Linux and Unix shell commands, which could also allow remote attackers to run unauthorized code on some systems.
Beard said that a similar update is planned for its Mozilla Suite browser, and the update is expected to be released by the end of the week.
Mozilla currently has a major update to Firefox in the testing phase, which is available in beta and will be released as Firefox 1.5.