Mozilla discloses more Firefox flaws
Patched 10 vulnerabilities in Firefox 3.6.2, reveals info on three bugs fixed last month
Computerworld - Editor's note: An earlier version of this story erroneously stated that Mozilla had released technical details of unpatched vulnerabilities. Those flaws were actually patched in February.Mozilla patched more than one vulnerability in Firefox when it updated the browser to version 3.6.2 on Monday, the company confirmed today.
A total of 10 flaws were fixed in Firefox 3.6.2, according to Mozilla's security advisory page, but details of others have been withheld until the company updates the older Firefox 3.0 and Firefox 3.5 browsers. Mozilla is scheduled to ship the updates, Firefox 3.0.19 and Firefox 3.5.9, next Tuesday, March 30.
Mozilla accelerated the release of Firefox 3.6.2 because a Russian researcher had announced a critical vulnerability in how the browser decodes the Web Open Font Format (WOFF), a Web-based font standard. Only Firefox 3.6 supports WOFF.
However, three of the vulnerabilities already patched in Firefox 3.6.2 also apply to older editions of the browser: One of the 10 fixed flaws that Mozilla ranked as "low" in its four step scoring system, one tagged as "high" and one marked as "critical."
Mozilla patched those bugs last month when it issued Firefox 3.0.18 and Firefox 3.5.8
Mozilla has rushed out fixes before, although -- like rival browser maker Microsoft -- it does so rarely. Last March, for example, Mozilla updated Firefox 3.0 to patch a pair of vulnerabilities, including one that had been used the week before by a German college student to hack the browser and take home $5,000 for his efforts at the Pwn2Own contest.
The bug quashed Monday -- and for a day, the only one for which information was published -- was disclosed by Russian researcher Evgeny Legerov in February. Initially, Legerov refused to provide proof of his exploit claims to Mozilla, prompting some to question his motives or wonder whether it was a hoax. According to Mozilla's Bugzilla change- and bug-tracking database, Legerov finally verified the vulnerability with the company's developers on March 13.
Mozilla has been under pressure to provide a patch. Last Friday, for instance, the German government's computer security agency urged users to abandon Firefox until a fix is available. Buerger-CERT, part of the Federal Office for Security in Information Technology, which is known by its German initials of BSI, retracted that recommendation yesterday, after Mozilla released Firefox 3.6.2.
Later today, Firefox -- as well as Microsoft's Internet Explorer, Google's Chrome and Apple's Safari -- will face several notable hackers at Pwn2Own, a contest that pits researchers against four notebooks running the browsers. Among those eager to go for the $5,000 cash prizes are two former winners, including a German college student who successfully exploited Firefox last year.
- Workarounds to purge search bar from Firefox's new tab page are available
- Mozilla ships Firefox 31, adds search to new tab page
- Microsoft's IE steps back from the brink of irrelevance
- Firefox falters, falls to record low in overall browser share
- Firefox risks user backlash by adding search box to new tab page
- Google unseats Microsoft as the U.S. browser powerhouse
- Safari, Chrome push to mask URLs
- Chrome on Windows champs at the 64-bit
- Google pulls trigger, cripples some Chrome add-ons
- Microsoft shoots to shorten Internet Explorer's long tail
- The Truth About Cloud Security "Security" is the number one issue holding business leaders back from the cloud. But does the reality match the perception?
- Enable secure remote access to 3D data without sacrificing visual perfomance Design and manufacturing companies must adapt quickly to the demands of an increasingly global and competitive economy. To speed time to market for...
- Virtually Delivered High Performance 3D Graphics "A picture is worth a thousand words." That old phrase is as true today as it ever was. Pictures (i.e., those with heavy...
- Best Practices for Securing Hadoop Historically, Apache Hadoop has provided limited security capabilities. To protect sensitive data being stored and analyzed in Hadoop, security architects should use a...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!