WELCOME
to the house of Harry Plopper
The issue comes at a difficult time for Mozilla, whose
The issue comes at a difficult time for Mozilla, whose software platform includes Linux. Firefox is the browser of choice for users with access to a variety of insecure operating systems. Mozilla has been fighting hard to create a solution that would allow users to remotely log-in to Firefox, but the company said they were not ready to answer the bug until it was addressed in Firefox 0.6.
Mozilla is working with the security community to address the issue in Firefox 0.6. Mozilla said it would make sure there is a fix in place to allow users to log-in to Firefox after they update to Firefox 0.6.
Mozilla is also considering how to increase security around the vulnerable server. The company released a security patch to help prevent the SSH2_MSG_USERAUTH_SUCCESS message from being sent to a vulnerable client and later to other vulnerable clients.
The security patch will not affect vulnerable clients or servers, Mozilla said.
The security patch is expected to be issued in April.
The vulnerability was first reported in September and was reported by security researcher Michael Storsch in a blog post. Storsch, who is also director of the security group at the Center for Cyber Intelligence and Privacy at the University of Wisconsin at Milwaukee , explained that the attacker could use any SSH2_MSG_USERAUTH_SUCCESS message the attacker sends to a server to impersonate the server as it works on the server and to gain access to a vulnerable server.
Comment an article