Firefox Update to 2.0.0.3 Fixes FTP Hole
|
Posted by Donster on: 2007-03-21 13:18:40 524
|
By Marcus Yam @ DailyTech
Mozilla has issued another minor update to its Firefox 2.0 web browser. New for Firefox 2.0.0.3 is a single security fix that patches up a hole in the browser’s FTP PASV functionality. A malicious web page hosted on a specially-coded FTP server could use this feature to perform a rudimentary port-scan of machines inside the firewall of the victim.
Mozilla says that by itself this causes no harm, but information about an internal network may be useful to an attacker should there be other vulnerabilities present on the network. Also new in 2.0.0.3 are fixes to improve Web site compatibility.
Firefox users can download 2.0.0.3 from Mozilla's homepage or use the auto update function within the browser.
|
News Source: Email
|
|