瀏覽單個文章
A.C
Master Member
 
A.C的大頭照
 

加入日期: Sep 2003
文章: 1,733
引用:
作者oToKo
拜託樓主不要只'看'片面之辭
Taiwan.CNET.com的新聞
如果長期觀察會發現
M$的銀彈攻勢(****?)有時會左右
新聞的報導取向
麻煩你看下:
Mozilla反駁Firefox 2漏洞說 (http://taiwan.cnet.com/news/softwar...20111064,00.htm)
看看FF方面的說明
平衡一下報導


oToKo 提供的訊息就是 Mozilla rebuts Firefox 2 bug reports 的中文版本。發布於 10 月 25 日。


以下是第一篇的英文版本,發布於 11 月 1 日。

Another denial-of-service bug found in Firefox 2
By Joris Evers, CNET News.com

A second security flaw that could cause the new Firefox 2 browser to crash has been publicly disclosed.

The vulnerability lies in the way the open-source browser handles JavaScript code. Viewing a rigged Web page will cause the browser to exit, a representative for Mozilla, the publisher of the software, said Wednesday. Contrary to claims on security mailing lists, the bug cannot be exploited to run arbitrary code on a PC running Firefox 2, the representative said.

This flaw in the JavaScript Range object is different from the denial-of-service vulnerability in Firefox 2 that was confirmed by Mozilla last week. That bug is related to a more serious security hole, which was fixed in earlier versions of Firefox, the organization has said.

The two "crashers" are the only publicly released vulnerabilities that have been confirmed by Mozilla in the week since Firefox 2 was launched. The issues are only minor, the organization has said.

By contrast, Microsoft's Internet Explorer 7 update suffers from a spoofing flaw, discovered a week after Microsoft released IE 7 on Oct. 18. The vulnerability could help crooks mask phishing scams, the type of attack Microsoft designed the browser to thwart.

According to Secunia, a security monitoring company, there are at least two other vulnerabilities in IE 7. Microsoft has disputed these issues, saying that one reported problem lies in Outlook Express, not IE 7, and the other is a part of the product design, not a flaw.

Release of the new Web browsers set off a race among bug hunters to come up with the first security hole in either program. So far, though, none of the reported flaws could be exploited to hijack a PC running the browser, the most serious type of vulnerability.
舊 2006-11-06, 01:47 PM #27
回應時引用此文章
A.C離線中