DesktopLinux
Home  |  News  |  Articles  |  Forum  |  Polls  |  Blogs  |  Videos  |  Resource Library

Keywords: Match:
Mozilla patches critical security flaws
Dec. 20, 2006

Mozilla Corp. today released a version 2.0.0.1 update for its Firefox browser and version 1.5.0.9 for its Thunderbird email client, for Linux, Mac OS X, and Windows machines. For those still using Firefox 1.5.x, version 1.5.0.9 includes the same security fixes.

The version 2.0.0.1/1.5.0.9 updates fix a number of critical security issues, a Mozilla spokesperson said, including:
  • XSS using outer window's Function object
  • RSS Feed-preview referrer leak
  • Mozilla SVG Processing Remote Code Execution
  • XSS by setting img.src to javascript: URI
  • LiveConnect crash finalizing JS objects
  • Privilege escalation using watch point
  • CSS cursor image buffer overflow (Windows only)
  • Crashes with evidence of memory corruption (rv:1.8.0.9/1.8.1.1)
Five of the vulnerabilities were listed as "critical" by Mozilla, with two described as "high" priority.

A "critical" vulnerability is defined as one that "can be used to run attacker code and install software, requiring no user interaction beyond normal browsing." A "high" vulnerability is one that "can be used to gather sensitive data from sites in other windows or inject data or code into those sites, requiring no more than normal browsing actions," the company said.

The company is in the process of notifying Firefox users through automatic updates. Uses who have not authorized automatic updates can download either of the new versions here. Thunderbird, which is now at version 1.5.0.9, can be downloaded immediately here.



Related Stories:


(Click here for further information)



Home  |  News  |  Articles  |  Forum  |  Polls  |  About  |  Contact
 

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
Tech RSS Feeds | ROI Calculators | Tech Podcasts | Tech Video | VARs | Channel News

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | Enterprise Network Security | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | Security IT Hub | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | igrep

Use of this site is governed by our Terms of Service and Privacy Policy. Except where otherwise specified, the contents of this site are copyright © 1999-2011 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise is prohibited. Linux is a registered trademark of Linus Torvalds. All other marks are the property of their respective owners.