Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Security Fixes and Improvements

July 21st, 2010, 10:55 GMT · By

Critical Security Update Available for Firefox

SHARE:

Adjust text size:


Firefox 3.6.7 addresses critical vulnerabilities
Enlarge picture
Mozilla has released Firefox 3.6.7, an update which addresses several security and stability issues. In total, eight critical, two high and four moderate security advisories were issued along with the new version of the popular browser.

According to Mozilla's severity rating system, vulnerabilities marked as critical allow attackers to execute arbitrary code remotely in a manner that is transparent to users. Even though there are eight security advisories marked as critical for this release, the number of critical bugs fixed is actually larger, because one advisory refers to several issues that could lead to memory corruption.

It is also noteworthy that five of the bugs were reported through TippingPoint's Zero Day Initiative (ZDI) program, where researchers are paid for discovered vulnerabilities. Another two critical bugs were found and reported by a Mozilla security researcher going by the online handle of moz_bug_r_a4. The “Mozilla developers and community” are credited with finding the issues in the collective advisory.

The final critical bug was actually located in libpng, a third-party developed reference library for processing PNG files. This vulnerability was found by a security researcher named Aki Helin and was patched in the latest version of libpng released at the end of June. However, since Firefox uses a private build of the library, Mozilla had to develop a patch of its own.

The two high severity issues, consist of a vulnerability, which can be leveraged to bypass the same-origin restrictions placed on a canvas element and read data from a different website, and a similar cross-origin data disclosure flaw bypassing the same-origin policy of JavaScript.

The four moderate advisories refer to vulnerabilities that can have a critical or high impact, but require special conditions to be exploited. One of them refers to two methods of spoofing the address displayed in the location bar, an attack that could prove very valuable for phishers. Another one allows for cross-domain data theft via CSS.

Users are strongly advised to upgrade to the new Firefox version immediately. People who haven't yet received the automatic update notification can manually trigger it by accessing Tools > Check for Updates from the browser's menu bar.

The Firefox 3.6.7 stand-alone installer for Windows can be downloaded from here.

The Firefox 3.6.7 stand-alone installer for Mac can be downloaded from here.

The Firefox 3.6.7 stand-alone installer for Linux can be downloaded from here.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

1,528 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Rogue Firefox Extension Hid in Security Add-Ons Collection

Mozilla Ramps Up Vulnerability Reward Program

New Firefox Extension Forces HTTPS Sessions on Popular Websites

Mozilla Confirms Critical Firefox Vulnerability

Exploit Code Available for Unpatched Firefox Bug

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM