Both Firefox and the Mozilla browser suite are vulnerable to attacks through flawed JavaScript engines, a security firm reported Monday.
The Mozilla Foundation's open-source browsers can be exploited by hackers to gain access to data currently in memory (but not information only stored on the hard drive), said the Danish security company Secunia.
According to Mozilla, use of a JavaScript "lambda" replace can expose arbitrary amounts of heap memory after the end of a JavaScript string. "Successful exploitation may disclose sensitive information in memory," said Secunia in its online alert.
|