Firefox BMP bugs

March 12th, 2008 Posted in Software

If you use Opera or Firefox browser, you need to be careful with your data. Recently, a security hole just found in this two popular browser. Firefox and Opera. Users may experience some problem when those browser handle cetain type of image and this vulnerability can be used to gather information such as history log.

Gynvael Coldwind, a computer savvy at vixillium.org, is the first who find out about this security bug. He post a video to illustrate the process. A remote user can view portions of kernel memory. A remote user create a specially crafted BMP file that, when loaded by the target user, will access uninitialized kernel memory then the information can be extracted using certain methods. This may be a chance for cyber thieve to steal important data from your history.

This bug is found in Firefox prior to version 2.0.0.12 and Opera Beta 9.50. If you still use this version, I recommend you to upgrade it. Latest version has issued a fix for the bug.

You can download latest Mozilla Firefox and Opera here.

Tags: ,

Leave a Reply