Several security vulnerabilities in Firefox and the Mozilla Suite of Internet software put users of the open-source products at risk of hacker attacks, the Mozilla Foundation is warning. The organization released Firefox 1.0.1, which fixes 17 security flaws in the popular Web browser. The most serious flaws could allow an attacker to gain full control over a victim"s PC, the Mozilla Foundation says in a statement. Firefox 1.0 was released in November and has since been downloaded more than 27 million times.
Firefox 1.0.1 also includes several fixes to guard against spoofing of Web addresses and the security indicator on Web sites. These vulnerabilities could be exploited for phishing scams, which typically use spam e-mail messages to drive people towards fraudulent Web pages that look like legitimate e-commerce sites. One of the changes made in Firefox 1.0.1 is in the way the browser handles international domain names (IDNs). These names are now displayed differently to make it easier to spot spoofed Web sites. Because of the way Firefox displayed IDNs, it was possible to register domain names with international characters that resembled other common characters, thus tricking users into believing they were on a trusted Web site.