Mozilla patches 16 security bugs in Firefox 3.6
Largest set of fixes since March includes patches for 9 critical flaws
Computerworld - Mozilla on Tuesday patched 16 vulnerabilities, nine of them critical, in Firefox 3.6, the largest update for the open-source browser since March.
At the same time, the company patched 12 flaws in the older Firefox 3.5.
More than half -- nine out of 16 -- of the vulnerabilities in Firefox 3.6 were rated "critical," Mozilla's highest threat ranking, indicating that hackers may be able to use them to compromise a system running Firefox, then plant other malware on the machine. Of the remainder, two were pegged as "high" risks, while the other five were labeled as "moderate."
Five of the vulnerabilities were reported to Mozilla by HP TippingPoint's Zero Day Initiative (ZDI), one of the two leading commercial bug bounty programs, while two were handed to Mozilla's developers by researchers who work for Google.
Earlier this month, Mozilla had said it was planning to ship Firefox patches before the annual Black Hat security conference, which is slated to start next week in Las Vegas. The company did the same last year, when it refreshed Firefox 3.0 with an 11-patch update just days before 2009's edition of the conference kicked off.
Mozilla currently has plans to produce another Firefox update after Black Hat, presumably to fix any flaws researchers disclose at the popular conference.
Software makers, especially browser developers, occasionally try to preempt potential security conference disclosures with updates. Prior to last March's CanSecWest, a Vancouver, British Columbia conference that features the Pwn2Own hacking contest, Google and Apple updated their Chrome and Safari browsers to fix several flaws.
Among the flaws fixed yesterday were two in the Firefox 3.6 rendering engine, one that could be exploited by posting malicious PNG images on sites, and two that might trick users into thinking they're at a trusted site when they actually are not.
Mozilla upgraded Firefox less than a week after it boosted bug bounties six-fold, to $3,000 for each vulnerability rated critical or high.
Unlike Google, which spells out the bounties it pays researchers in its security advisories, Mozilla does not spotlight the vulnerabilities it's bought. According to the criteria it laid out last week, however, Mozilla may have spent as much as $21,000 for seven of the flaws it fixed Tuesday.
Users can update to Firefox 3.6.7 by downloading the new edition or by selecting "Check for Updates" from the Help menu in the browser. Firefox 3.5 users can obtain the patched version 3.5.11 by calling up the integrated update tool.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is email@example.com.
- Google reverses field, promises to restore Chrome's scrollbar arrows
- Update: Google ships Chrome 33, patches 28 bugs
- Mozilla's top exec defends in-Firefox ads, revenue search
- Mozilla taps in-Firefox ads as it searches for more revenue
- Mozilla ships Metro Firefox beta for Windows 8
- Mozilla defers Firefox's new 'Australis' UI to April
- Mozilla resets Metro Firefox ship date to mid-March
- Mozilla ships Firefox 26 with opening click-to-play move
- Mozilla banked $274M in '12 from Google-Firefox search deal
- Google trumpets Chrome's SPDY gains
Read more about Desktop Apps in Computerworld's Desktop Apps Topic Center.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Pay-as-you-Grow Data Protection: IBM Tivoli's Full-featured Data Protection Suite for Small to Medium Businesses IBM Tivoli Storage Manager Suite for Unified Recovery gives small and medium businesses the opportunity to start out with only the individual solutions...
- Streamline Data Protection with IBM Tivoli Storage Manager Operations Center IBM Tivoli Storage Manager (TSM) has been an industry-standard data protection solution for two decades. But, where most competitors focus exclusively on Backup...
- Simplify and Consolidate Data Protection for Better Business Results Learn about IBM® Tivoli® Storage Manager Operations Center, which provides advanced visualization, built-in analytics and integrated workflow automation features that leapfrog traditional backup...
- HP HAVEn: See the big picture in Big Data HP HAVEn is the industry's first comprehensive, scalable, open, and secure platform for Big Data. Enterprises are drowning in a sea of data...
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well...
- The New Way to Work Knowledge Vault This Knowledge Vault focuses on how, in today's increasingly virtual world, it's more important than ever to engage deeply with employees, suppliers, partners,... All Desktop Apps White Papers | Webcasts