New Version of Firefox Patches 2 Flaws

MOUNTAIN VIEW, Calif. — Less than two weeks after the release of Firefox 2.0.0.5, the Mozilla Foundation has released Firefox 2.0.0.6 in order to address a pair of vulnerabilities present in the previous version of the browser, Mozilla announced today.

Flaws in Firefox are of growing concern to the adult Internet industry because of Firefox’s growing share of the browser market.

The more critical of the two flaws concerns the encoding of URLs that are handed off to external programs, an issue that the Mozilla team had rated as a "critical" flaw.

Researcher Jesper Johansson originally reported the flaw, observing that Firefox did not percent-encode spaces and double-quotes in uniform resource identifiers (URIs) that were passed to external applications, which resulted in the possibility that the receiving program could interpret an incoming single URI as multiple arguments — an error that had also been observed in Internet Explorer.

In Firefox 2.0.0.5, Mozilla introduced code to handle URLs passed to Firefox that included unfixed quotes and spaces, and version 2.0.0.6 ensures that Firefox properly percent-encodes those strings before passing them to external programs.

The less serious vulnerability addressed in the 2.0.0.6 release was a flaw that allowed “privilege escalation” — exploiting a bug to access resources that would normally be reserved for an administrator and protected from mere users — by manipulating add-ons in Firefox 2.0.0.5.

According to web metrics tracking firm Net Applications, Firefox’s share of the browser market increased from 9.5 percent in January 2006 to more than 13.6 percent in January of this year.

A competing web metrics firm, OneStat, claims that Firefox’s growth was smaller in the same period, but reports Firefox’s total market share is higher: 16.11 percent as of January.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Aylo Willing to Work With Australia's Online Censor on Device-Based AV Solutions

The office of Australia’s top online censor, unelected eSafety Commissioner Julie Inman Grant, released a new roadmap for implementing age verification according to the country’s Online Safety Act.

Spain's Technology Minister Unveils Soon-to-be-Mandatory Age Verification App

Spain’s anti-sex work and anti-porn Socialist Party (PSOE) government led by Prime Minister Pedro Sánchez unveiled a new age verification app that will become a mandatory step to access any adult content by anyone in the country starting in September.

FSC Drops Opposition to California Age Verification Bill After Amendments

Free Speech Coalition (FSC) has dropped its formal opposition to California’s age verification bill AB 3080, after an amendment secured through months of discussions with the bill’s author was heard by the Senate Judiciary Committee.

SCOTUS Agrees to Hear Texas Age Verification Challenge

The United States Supreme Court granted on Tuesday the petition for a writ of certiorari in the Free Speech Coalition-led challenge to Texas’ age verification law, agreeing to hear the case in the next term.

Dorcel Group Acquires LifeSelector

Dorcel Group has acquired interactive content company LifeSelector.

Etsy Updates Policy to Ban Sale of Most Adult Pleasure Products, Content

Etsy will ban sales of most pleasure products and content that depicts sex acts and genitalia starting July 29.

Jamie Page Is LoyalFans' 'Featured Creator' for July

LoyalFans has named Jamie Page as its Featured Creator for July.

Byborg's Le Shaw Research Institute Teams Up With SWOP Behind Bars

LiveJasmin parent company Byborg Enterprises’ Le Shaw International Sexual Health and Wellness Research Institute has joined forces with U.S.-based sex worker advocacy group SWOP Behind Bars.

AI Erotic Storytelling Platform 'Erota' Launches

Erota, a new AI-powered erotic storytelling platform, has debuted.

Indiana Court Blocks Age Verification Law

A U.S. district court in Indiana has blocked the state's age verification law from taking effect this coming Monday, July 1.

Show More