Tuesday, November 14, 2006

Mozilla Patches Digital Signature Bug

There is a bug in the way that Mozilla Firefox, Thunderbird, and SeaMonkey handle RSA digital signatures. If the signatures use a low exponent, they could be forged. Mozilla fixed this in Firefox 2, but the fix was incomplete in Firefox 1.5.0.7. They have come out with a bug fix release, Firefox and Thunderbird version 1.5.0.8, and SeaMonkey 1.0.6, to take care of this and a few other bugs. Mozilla credits Ulrich Kuehn for finding this bug.