Mozilla debuts in-browser PDF, patches 13 Firefox bugs

Argues that new built-in PDF view will keep users safer

By , Computerworld |  Security, Firefox, Mozilla

"I would have to imagine that it has just as much potential to have bugs as any other software," said Andrew Storms, director of security operations at nCircle Security, in an interview Tuesday conducted via instant messaging. "It would appear they are banking on the open-source community to provide better security than the closed source commercial PDF viewer from Adobe. By pulling the PDF reader 'in house' via an open-source initiative, it lets them release bug fixes much faster and on their own schedule."

Storms was echoing comments made last month by other security professionals.

Firefox 19 renders PDF documents for viewing and printing without requiring a separate plug-in, following a 2010 move by Google's Chrome.

Mozilla acknowledged that the viewer was not protected by any special defense, as are malformed PDFs in Adobe's Reader -- at least on Windows, which provides a full-fledged sandbox -- or in Google's Chrome, which sandboxes each tab, isolating a rigged PDF from the rest of the browser.

"PDF.js runs with the same permissions as any Web page though, so there would have to be a security problem with Firefox itself," tweeted the PDF.js team last month in reply to a question about potential security issues with the viewer.

Today, Mozilla stuck to its argument that third-party plug-ins are less secure than Firefox itself, and by burying the PDF viewer inside the browser, users will face fewer threats. "Third-party plug-ins are the number one source of security and stability issues in Web browsers," Johnathan Nightingale, who leads Firefox engineering, said in an email, echoing similar statements by other browser makers. "Firefox uses a JavaScript library called PDF.js instead of handing off to other software...[and] because this support is implemented in JavaScript with the same level of privilege as any other Web page, it avoids many of the memory safety vulnerabilities that have plagued stand-alone plug-ins."

But Storms noted the flip side. "So if this PDF process, as part of Firefox, has a hole, the attacker in theory then owns the browser instead of just the plug-in process," Storms said.

Mozilla also patched 13 vulnerabilities, 10 critical, one marked "high" and two pegged "moderate," in Firefox today.

Nearly half of the bugs were reported by Abhishek Arya, better known as "Inferno," of the Chrome security team, Mozilla said in one of today's advisories, making this the third Firefox upgrade running where Arya has accounted for a major part of the reported vulnerabilities.

Originally published on Computerworld |  Click here to read the original story.
Join us:






Answers - Powered by ITworld

Ask a Question