Firefox Update to 2.0.0.3 Fixes FTP Hole

News Posted 21/03/07
Author: PV5150
Source: DailyTech


FireFox logo

Mozilla has issued another minor update to its Firefox 2.0 web browser. Version 2.0.0.3 is a single security fix that patches up a hole in the browser’s FTP PASV functionality.

A malicious web page hosted on a specially-coded FTP server could use this feature to perform a rudimentary port-scan of machines inside the firewall of the victim. Mozilla says that by itself this causes no harm, but information about an internal network may be useful to an attacker should there be other vulnerabilities present on the network. Also new in 2.0.0.3 are fixes to improve Web site compatibility.

Discuss in our forum