Genealogy Chat

Top tip - using the Genes Reunited community

Welcome to the Genes Reunited community boards!

  • The Genes Reunited community is made up of millions of people with similar interests. Discover your family history and make life long friends along the way.
  • You will find a close knit but welcoming group of keen genealogists all prepared to offer advice and help to new members.
  • And it's not all serious business. The boards are often a place to relax and be entertained by all kinds of subjects.
  • The Genes community will go out of their way to help you, so don’t be shy about asking for help.

Quick Search

Single word search

Icons

  • New posts
  • No new posts
  • Thread closed
  • Stickied, new posts
  • Stickied, no new posts

Firefox Users Beware!!

ProfilePosted byOptionsPost Date

Merlin38

Merlin38 Report 19 Feb 2008 18:02

Have just picked up this advisory notice.

A flaw in the way the Firefox and Opera browsers handle an image file could allow an attacker to see what sites a person has visited.

The problem concerns how the two browsers handle a ".BMP," or bitmap, image file, according to an advisory written by Gynvael Coldwind of Vexillium.org, who posted a video illustrating the problem.

A malicious bitmap file can be created that pulls other information from the browsers' memory. Some of the information that can be captured is random, but at other times could be valuable, the advisory said.

"The harvested data contains various information including parts of other websites, users' favourites and history and other information," Vexillium.org said.

Using the "canvas" HTML (Hypertext Markup Language) tag supported by the browsers, an attacker can capture the data. Then, using JavaScript, the information can be sent to a remote server.

The flaw could also crash Firefox. The vulnerability affects Firefox 2.0.0.11 and previous versions of that browser

David

Alan

Alan Report 19 Feb 2008 20:06

The latest version is 2.0.0.12 so everyone should really be using this version by now as it has been out since February 8th.

gemqueen

gemqueen Report 19 Feb 2008 20:19

Checked mine and have version 2.0.0.12
Thanks
Di