Firefox Fends Off QuickTime Bug Threat
By Nancy Cohen
LinuxInsider
Part of the ECT News Network
09/20/07 3:30 PM PT
Mozilla developers immediately closed ranks to come up with a solution. "To protect Firefox users from this problem we have now eliminated the ability to run arbitrary script from the command-line," Mozilla announced Tuesday. "Other command-line options remain, however, and QuickTime Media-link files could still be used to annoy users with popup windows and dialogs until this issue is fixed in QuickTime."

Better Email Security Just Got A Whole Lot Easier. And Cheaper. Introducing Security Software As A Service From Webroot. Free 14-Day Trial.
Empathy at Opera
Opera, a second-row contender to diva browsers Internet Explorer and Firefox, is not gloating over Mozilla's bug flap, however.
"We can say that it proves that making a Web browser is a complicated business," Thomas Ford, Opera global communications manager
, told LinuxInsider.
"We have always felt a responsibility for keeping our users as safe as we can. Having to account for third-party plug-ins and applications makes this trickier," he said.
Closed Ranks
Mozilla developers immediately closed ranks to come up with a solution. "To protect Firefox users from this problem we have now eliminated the ability to run arbitrary script from the command-line," Mozilla announced Tuesday.
"Other command-line options remain, however, and QuickTime Media-link files could still be used to annoy users with popup windows and dialogs until this issue is fixed in QuickTime," the announcement said.
Writing NoScript
One of the Mozilla stormtroopers is Giorgio Maone, a Palermo, Italy, software developer who is the author of NoScript, which blocks malicious script.
"When the recent QuickTime-based exploit pointed out that the problem had not been entirely addressed, NoScript users were still entirely safe," Maone told LinuxInsider.
Mozilla developers, in reaching their solution, came up with an approach similar to NoScript's, according to Maone.
Add-On Protection
Mozilla's advisory pointed out that the "NoScript add-on, however, has provided protection against this class of attack since the cross-browser vulnerabilities were discovered."
NoScript has a "forbid other plug-ins" option that allows users to choose sites they trust. Executable content runs only from trusted domains of choice. "NoScript's commitment is providing maximum security for users who want a flexible tool allowing them to stay in control and choose the sites that can run programs inside their browsers," Maone said.
Nimble Response
The incident proves that the Mozilla community can rise to the occasion of a bug threat promptly. "A six-day timeframe to patch this bug is a glaring testament to the unparalleled reactivity of Mozilla developers," Maone said.
"Mozilla developers chose to put their strongest efforts in working around it. This tells a lot about the responsibility and commitment of the Mozilla community when users' safety is at stake," he said. "Another vendor could have just blamed Apple."