12/18/2008

Firefox Issues Rash of Security Fixes

Filed under: — Aviran Mordo @ 4:12 am

While Microsoft scrambled to issue an out-of-cycle patch for Internet Explorer on Wednesday, Mozilla did some rushing of its own.

The Firefox developer has issued updates to address “critical vulnerabilities” in versions 2 and 3 of its open-source browser.

Firefox describes a critical vulnerability as one that can be used to run attacker code and install software without user interaction beyond normal browsing.

Security, Stability, Accessibility

Firefox 3.0.5 and Firefox 2.0.0.19 are now available for Windows, Mac and Linux. Firefox 3.0.5 fixes eight security vulnerabilities, three of them critical. The critical fixes include XSS vulnerabilities in SessionStore, XSS and JavaScript privilege escalation, and crashes with evidence of memory corruption.

The Firefox 3.0.5 update also fixes several stability issues and issues found in accessibility implementation, adds the ability to send OS-specific system notes in the crash reporter, and replaces the End-User License Agreement with a new “Know Your Rights” info bar on the initial installation.

 

Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress