Technology news and Jobs arrow VIRTUALISATION arrow More flaws fixed in Firefox
More flaws fixed in Firefox E-mail
by Stephen Withers   
Wednesday, 05 August 2009
Firefox 3.5.2 fixes a quartet of security issues - two of them rated critical - along with a display-related bug. Security fixes are also delivered in version 3.0.13.

New versions of the popular Firefox open-source browser have been released to overcome various vulnerabilities.

Version 3.5.2 fixes two critical issues, one allowing a privilege escalation, and the other involving instabilities with the potential to allow the execution of arbitrary code.

3.0.13 also fixes a potential arbitrary code vulnerability, and the incorrect handling of SSL certificates (allowing attackers to spoof supposedly secure sites such as banks, or to send maliciously crafted certificates to cause the execution of arbitrary code).

One moderate fix applying to both versions addresses a problem that could be use to spoof the URL and SSL indicator on a malicious page.

3.5.2 also overcomes a low-impact issue involving data corruption that occurred when a SOCKS5 proxy sends a reply containing a DNS name that is longer than 15 characters.

The other bug fix in 3.5.2 means that images with ICC profiles are now rendered properly on all monitors.

The most convenient way for users of Firefox on Windows or Mac OS X to obtain the new version(s) is to take advantage of the Check for Updates command as this avoids the need to download the entire installer.

Firefox 3.5.1 was released less than three weeks ago. And that was less than three weeks after the debut of Firefox 3.5.

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter