The flaw in Mozilla Firefox 1.0, details of which were published by security company Secunia on Tuesday, allows malicious hackers to spoof the URL in the download dialog box that pops up when a Firefox user tries to download an item from a Web site. This flaw is caused by the dialog box incorrectly displaying long sub-domains and paths, which can be exploited to conceal the actual source of the download.
Mikko Hypponen, director of antivirus research at software maker F-Secure, said this bug could make Firefox users vulnerable to cybercriminals. “The most likely way we could see this exploited would be in phishing scams,” he said.
Read the Compete Story @ ZDnet NewsRelated Posts
- Firefox 1.0.7 Released
- Firefox 1.0.7 Released
- Firefox 1.5.0.5 update plugs ‘critical’ holes
- Symantec flaw leaves opening for viruses
- Microsoft warns of ‘important’ Windows flaw
Zeropaid on Facebook

