Monday, May 09, 2005

Two Security Holes in Firefox

The advisory explains that the successful attacks involve two elements. The first flaw fools the browser into thinking software is being installed by a "whitelisted site." The second flaw occurs when the software installation trigger does not sufficiently check icon URLs containing JavaScript code.
Users can protect themselves by temporarily disabling JavaScript, according to Mozilla.

No comments: