Mozilla patches critical Firefox bugs
No need to update newest edition, Firefox 3.6; flaws already fixed
Computerworld - Mozilla on Wednesday patched five vulnerabilities, three of them critical, in older editions of Firefox and in the process extended the support life of Firefox 3.0 by at least one more month.
The newest Mozilla browser, Firefox 3.6, already contains the patches.
Firefox 3.5.8 and Firefox 3.0.18 address three critical flaws in the browsers' Gecko rendering engines, the HTML parsers, and their implementations of Web Worker, an enhanced scripting functionality that lets site developers shift JavaScript computations to a background thread to reduce the performance hit on Firefox's user interface.
Hackers able to exploit any of the three critical bugs would be able to inject their own malware onto the machine, Mozilla noted in the accompanying advisories. "Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code," read the advisory dedicated to the browser engine issue.
The remaining two vulnerabilities , both rated "moderate" in Mozilla's four-step scoring system, were bugs that could be exploited in cross-site scripting attacks.
One of the cross-site scripting flaws was reported by a security researcher working for browser rival Microsoft, marking the second time in two days that Microsoft experts were credited with passing along vulnerability information to a competitor. Yesterday, Adobe said Microsoft had found and reported a critical flaw in Reader and Acrobat.
Firefox 3.6 does not need to be updated; the five vulnerabilities were addressed before Mozilla shipped the browser Jan. 21.
The last time that Mozilla issued a security update for Firefox was Jan. 5, when it fixed a flaw in the browser's upgrade mechanism and patched a bug that programmers inadvertently introduced the month before.
With the update to Firefox 3.0.18, Mozilla also extended the support lifespan of the 2008 browser beyond the January cutoff it had earlier announced. Mozilla did not immediately respond to questions about when it plans to officially retire the version. In the past, Mozilla has discontinued security updates for a browser approximately six months after the release of a newer edition; Firefox 3.5, the immediate successor to version 3.0, shipped on June 30, 2009.
Firefox accounts for 24.4% of the browser market, according to the most recent data from metrics company NetApplications.com. Over three-fourths of Firefox users ran version 3.5 last month, while the remainder ran the older 3.0.
Firefox 3.5.8 can be downloaded for Windows, Mac OS X and Linux from the Mozilla site. Current Firefox users can instead call up the browsers' update tools, or wait for automatic update notifications to appear in the next 48 hours.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@ix.netcom.com.
Browser wars
- Mozilla to Firefox: 'Browser, heal thyself'
- Best case, Mozilla's Firefox for Windows 8 will ship in October
- Microsoft's browser auto-update pays off as IE10 share doubles
- Sued Opera designer fingers Mozilla's 'Search Tabs' as root of $3.4M claim
- Update: Opera slaps former designer with $3.4M lawsuit for spilling secrets
- As browsing goes mobile, Apple wins, Mozilla loses
- Mozilla pulls tracking trigger for Firefox 22, ignores ad industry attacks
- Mozilla refines Firefox's private browsing, patches 13 browser bugs
- Mobile's browser usage share jumps 26% in three months
- Mozilla again rejects porting Firefox to iOS
Read more about Web Apps in Computerworld's Web Apps Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Anticipate, Engage and Deliver Exceptional Web Experiences IBM Customer Experience Suite and IBM Intranet Experience Suite help organizations delight customers through a consistently exceptional web experience and empower employees with...
- Harness IT -- An Introduction to Business Intelligence Solutions Learn the key selection criteria required to provide your organization with the capability to address structured data, unstructured data and mobile demands so...
- Business Intelligence Shows its Smarts Today's Business Intelligence (BI) tools provide a new way to think about data with self-service capabilities and user-friendly analytics that can be used...
- Proactive Planning for Big Data Big data is less about the terabytes and more about the query tools and business intelligence needed to make sense of massive amounts...
- Becoming An Analytics Driven Organization Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in... All Web Apps White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!
