Computers |
|
| | #1 (permalink) |
| Security/Hacking Mod Join Date: Jan 2005 Location: USA
Posts: 24,083
| Mozilla coughed its latest Firefox update this week and patched ten flaws – five of which were critical vulnerabilities – in the latest version of its browser. The firm said it strongly recommended that Firefox fanciers upgrade to version 2.0.0.13 because of the number of security fixes built into the latest update. Critical flaws that have now been patched in the Internet Explorer rival include a brace of exploits that could crash Firefox or its JavaScript engine and cause an arbitrary code execution. The update, which applies to Windows, Mac and Linux-based machines, was pushed out automatically by Mozilla earlier this week. Other vulnerabilities that have now been patched include a privacy issue with SSL client authentication, an HTTP referrer spoofing bug and a fix for a Java socket connection to any local port via LiveConnect. However, the firm has not built the fixes into the latest version of its mail client Thunderbird, even though it shares five of the flaws. Mozilla’s David Ascher said on his blog last week that patches will not be available for “several weeks”. In the meantime the firm advised the following: "Thunderbird shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail. "This is not the default setting, and we strongly discourage users from running JavaScript in mail." Mozilla plugs 10 security holes in Firefox | The Register Last edited by Osiris; 03-27-2008 at 09:56 AM. |
| | |
| | #2 (permalink) |
| Tech-Forums Management Das BanHammer Join Date: Jan 2005 Location: The South
Posts: 13,931
| Good to see them getting the kinks out. No matter what browser you use, it is always a good thing when the patch the holes, eh?
__________________ Avatar created by pokernod ![]() CoolerMaster WaveMaster (black) - Vantec Stealth 520W DFI LanParty UT nF4 SLI-D - AMD Athlon X2 4200+ - Zalman CNPS9500 2GB (2x1 GB) G.SKILL ZS - Seagate 80GB, 250GB SATA - Razer Lachesis ATI 3850 w/Accelero S1 - NEC 19" MultiSync 1970GX RegistryBooster, SpeedUpMyPC, SpyEraser, WinTasks - Uniblue Free Software Trials |
| | |
| | #3 (permalink) |
| Commander Super Mod Joker Join Date: Sep 2004 Location: In Trotter's crawl space
Posts: 14,307
| That is what matter most. Getting the flaws fixed. Some are fast like Opera or Mozilla that get it done in a day or week. Then you have those that wait for they update cycle. *whistles* But in the end getting it fixed is what matters. Keeping people safe on the web. |
| | |
![]() |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Opera screeches at Mozilla over security disclosure | Osiris | Browser & General Internet Questions | 4 | 02-19-2008 05:19 AM |
| Firefox Security and Stability Update | Osiris | Windows Operating Systems and Software | 8 | 02-09-2008 01:19 PM |
| Mozilla Says Firefox Flaw Could Lead To Data Leak | Osiris | Windows Operating Systems and Software | 18 | 01-24-2008 09:39 PM |
| Mozilla Firefox May Disclose Files or Information to Remote Users | Osiris | Virus - Spyware Protection / Detection | 2 | 10-20-2007 04:03 PM |
| Critical Security Flaw Discovered In IE & Firefox | Osiris | Browser & General Internet Questions | 6 | 07-18-2007 08:04 PM |