Firefox 3 security compromised

Firefox 3 security flaw reported
Firefox 3 security flaw reported

Somebody has already reported a serious security flaw with Mozilla's latest version of Firefox that was released and downloaded by millions of users last week.

The security flaw was reported to TippingPoint's Zero Day Initiative and Mozilla has been informed of the details, so we will no doubt see a fix for the problem in the next Firefox 3 update.

We are waiting to hear on more details about that from Mozilla, so will be sure to keep you informed.

Cashing in?

As the vulnerability also affects the older version of Mozilla's Firefox 2, there is always the suspicion that the person who flagged the problem with TippingPoint was waiting until Firefox 3 launched with all the accompanying hype and fanfare last week, to cash-in a little more on their discovery.

Bear in mind that The Zero Day Initiative Benefits lists the following factors in determining the value of a reported fault:

• Is the affected product widely deployed?
• Can exploiting the flaw lead to a server or client compromise? At what privilege level?
• Is the flaw exposed in default configurations/installations?
• Are the affected products high value (e.g. databases, e-commerce servers, DNS, routers, firewalls)?
• Does the attacker need to social engineer his victim? (e.g. clicking a link, visiting a site, connecting to a server, etc.)

Internet best practice

Details on the security breach are scarce. The Tipping Point blog merely notes that: "Successful exploitation of the vulnerability could allow an attacker to execute arbitrary code. Not unlike most browser based vulnerabilities that we see these days, user interaction is required such as clicking on a link in email or visiting a malicious web page."

While we await further details on the manner of the security threat, we can only advise that you don't click on any suspicious links in non-solicited emails or visit dodgy websites!

In the meantime, concerned Firefox 3 users might want to install the useful NoScript extension, just to be sure.

Adam Hartley
Latest in Browsers
Woman using a Windows computer with Microsoft Edge
Don’t panic – Microsoft’s Edge browser isn’t about to subject you to a flood of unblocked adverts (not yet, anyway)
Google Chrome browser icon
A new split-screen feature is coming to Google Chrome, and it's surprisingly powerful
The Microsoft Edge logo on a black background displayed on a laptop screen.
Microsoft just gave Edge a great new feature to ensure the browser doesn’t slow down the PC, and it’s tempting me to switch from Google Chrome
Google Chrome with Christmas theme in Windows 11
I've used Edge, Firefox, and Opera, and yet after ten years in tech journalism, I still come back to Chrome
Woman using a Windows computer with Microsoft Edge
Microsoft gets rid of ‘Edge uninstall’ advice page after facing criticism over it having nothing to do with removing the app, and just promoting the browser instead
Microsoft Edge
Sorry, you're not getting Microsoft Edge off of your PC, at least according to its new 'uninstall' document
Latest in News
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what's happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
US flags
US government IT contracts set to be centralized in new Trump order
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping