Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Mozilla patches 13 Firefox bugs, launches in-browser PDF

Built-in PDF view will keep users safer, Mozilla claims

Article comments

Mozilla has released Firefox 19, adding a built-in PDF viewer to the browser and patching 13 security vulnerabilities.

The integrated viewer was the one noticeable change to users, although Mozilla enhanced under-the-hood features as well for website developers, and added support for additional HTML5 standards.

Firefox 19 also included patches for 13 security vulnerabilities, 10 pegged as "critical," the company's most severe threat ranking.

But the inclusion of a PDF viewer was what Firefox users will see. The viewer was once slated for Firefox 18 -- it was part of that edition's beta -- but Mozilla pulled the component before shipping the browser early last month, delaying it until the next iteration in its every-six-week release cycle.

Firefox's PDF viewer came out of a Mozilla Labs project initially dubbed "PDF.js," the "js" for JavaScript, which along with HTML5 APIs (application programming interfaces), was used to build the browser's viewer.

With the move, Mozilla follows in Google's footsteps: The search giant baked a PDF viewer into Chrome more than two years ago.

But unlike Chrome's PDF viewer, which operates inside the browser's anti-exploit sandbox, Firefox's does not sport similar defenses. And that matters, as PDF documents are often rigged with malicious code.

Adobe, for example, said last weekend that it plans to patch the Reader plug-in this week to stifle attacks exploiting a pair of vulnerabilities. And Foxit, another popular PDF browser plug-in, quashed a bug of its own less than five weeks ago.

Even sans a sandbox, Mozilla claimed its PDF viewer would be more secure than traditional plug-ins such as Adobe Reader. "Many of these plug-ins come with proprietary, closed source code that could potentially expose users to security vulnerabilities," said Bill Walker and Brendan Dahl, engineering manager and software engineer at Mozilla, respectively, in a January blog announcing the viewer.

But security experts have pointed out that Firefox's PDF viewer will likely suffer bugs of its own.

"I would have to imagine that it has just as much potential to have bugs as any other software," said Andrew Storms, director of security operations at nCircle Security, in an interview Tuesday conducted via instant messaging. "It would appear they are banking on the open-source community to provide better security than the closed source commercial PDF viewer from Adobe. By pulling the PDF reader 'in house' via an open-source initiative, it lets them release bug fixes much faster and on their own schedule."

Storms was echoing comments made last month by other security professionals.

Firefox 19 renders PDF documents for viewing and printing without requiring a separate plug-in, following a 2010 move by Google's Chrome.

Mozilla acknowledged that the viewer was not protected by any special defense, as are malformed PDFs in Adobe's Reader -- at least on Windows, which provides a full-fledged sandbox -- or in Google's Chrome, which sandboxes each tab, isolating a rigged PDF from the rest of the browser.

"PDF.js runs with the same permissions as any Web page though, so there would have to be a security problem with Firefox itself," tweeted the PDF.js team last month in reply to a question about potential security issues with the viewer.

Today, Mozilla stuck to its argument that third-party plug-ins are less secure than Firefox itself, and by burying the PDF viewer inside the browser, users will face fewer threats. "Third-party plug-ins are the number one source of security and stability issues in Web browsers," Johnathan Nightingale, who leads Firefox engineering, said in an email, echoing similar statements by other browser makers. "Firefox uses a JavaScript library called PDF.js instead of handing off to other software...[and] because this support is implemented in JavaScript with the same level of privilege as any other Web page, it avoids many of the memory safety vulnerabilities that have plagued stand-alone plug-ins."

But Storms noted the flip side. "So if this PDF process, as part of Firefox, has a hole, the attacker in theory then owns the browser instead of just the plug-in process," Storms said.

Mozilla also patched 13 vulnerabilities, 10 critical, one marked "high" and two pegged "moderate," in Firefox today.

Nearly half of the bugs were reported by Abhishek Arya, better known as "Inferno," of the Chrome security team, Mozilla said in one of today's advisories, making this the third Firefox upgrade running where Arya has accounted for a major part of the reported vulnerabilities.

Three of the six reported by Arya were use-after-free vulnerabilities, a type of memory management bug that Google's security engineers have rooted out in droves from Chrome and, increasingly, other browsers.

Another of the baker's dozen, also a use-after-free bug, was reported by a researcher known only as "Nils," who is best known for back-to-back victories at the 2009 and 2010 Pwn2Own hacking contests.

Windows, Mac and Linux editions of Firefox 19 can be downloaded manually from Mozilla's site. Already-installed copies will upgrade automatically.

The next version of Firefox is scheduled to ship April 2, 2013.


More from Techworld

More relevant IT news


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *