Technology news and Jobs arrow VIRTUALISATION arrow Critical bug - and more - fixed in Firefox 3.0.9
Critical bug - and more - fixed in Firefox 3.0.9 E-mail
by Stephen Withers   
Thursday, 23 April 2009
A new version of the popular Firefox browser fixes several security flaws and other bugs. This time, only one of the security issues is rated critical.

Firefox 3.0.9 addresses nine security issues. The critical issue concerns stability problems with evidence of memory corruption, and there is a presumption that one or more of the bugs could be exploited to run arbitrary code.

Two of these problems have been shown to also affect the no longer supported Firefox 2, providing another reason to upgrade if you can. (Firefox's hardware requirements are modest, but if you're out of luck if you're still running Windows 98 or Mac OS X 10.3.)

High-impact vulnerabilities involve a mishandling of Flash files that could result in cross-site attacks or privacy violations, and a JavaScript problem that could allow the execution of a script with incorrect privileges.

Moderate vulnerabilities concern the mishandling of .jar files and a bug in the handling of Refresh headers.

The low-impact vulnerabilities involve data leakage, code injection by malicious search plugins, cross-site scripting opportunities in third-party stylessheets, and URL spoofing with characters that should have been disallowed.

Other changes include fixing bugs concerning cookie storage, the display of inline images in webmail, and the slow submission of large forms.

Unspecified stability issues have also been addressed.

Existing installations can be updated using Firefox's Check for Updates command, or the browser can be downloaded afresh from Mozilla's site.
Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter