Mozilla patches 16 security bugs in Firefox 3.6
Largest set of fixes since March includes patches for 9 critical flaws
Computerworld - Mozilla on Tuesday patched 16 vulnerabilities, nine of them critical, in Firefox 3.6, the largest update for the open-source browser since March.
At the same time, the company patched 12 flaws in the older Firefox 3.5.
More than half -- nine out of 16 -- of the vulnerabilities in Firefox 3.6 were rated "critical," Mozilla's highest threat ranking, indicating that hackers may be able to use them to compromise a system running Firefox, then plant other malware on the machine. Of the remainder, two were pegged as "high" risks, while the other five were labeled as "moderate."
Five of the vulnerabilities were reported to Mozilla by HP TippingPoint's Zero Day Initiative (ZDI), one of the two leading commercial bug bounty programs, while two were handed to Mozilla's developers by researchers who work for Google.
Earlier this month, Mozilla had said it was planning to ship Firefox patches before the annual Black Hat security conference, which is slated to start next week in Las Vegas. The company did the same last year, when it refreshed Firefox 3.0 with an 11-patch update just days before 2009's edition of the conference kicked off.
Mozilla currently has plans to produce another Firefox update after Black Hat, presumably to fix any flaws researchers disclose at the popular conference.
Software makers, especially browser developers, occasionally try to preempt potential security conference disclosures with updates. Prior to last March's CanSecWest, a Vancouver, British Columbia conference that features the Pwn2Own hacking contest, Google and Apple updated their Chrome and Safari browsers to fix several flaws.
Among the flaws fixed yesterday were two in the Firefox 3.6 rendering engine, one that could be exploited by posting malicious PNG images on sites, and two that might trick users into thinking they're at a trusted site when they actually are not.
Mozilla upgraded Firefox less than a week after it boosted bug bounties six-fold, to $3,000 for each vulnerability rated critical or high.
Unlike Google, which spells out the bounties it pays researchers in its security advisories, Mozilla does not spotlight the vulnerabilities it's bought. According to the criteria it laid out last week, however, Mozilla may have spent as much as $21,000 for seven of the flaws it fixed Tuesday.
Users can update to Firefox 3.6.7 by downloading the new edition or by selecting "Check for Updates" from the Help menu in the browser. Firefox 3.5 users can obtain the patched version 3.5.11 by calling up the integrated update tool.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@ix.netcom.com.
Browser wars
- Microsoft wraps up ads aimed at Google with IE9 pitch
- German gov't endorses Chrome as most secure browser
- Google's punishment of Chrome drops browser's share, says metrics firm
- Firefox 10 relieves add-on updating pain
- Mozilla OKs Firefox 10 launch this week
- Google patches several serious Chrome bugs
- Mozilla slows pace of Firefox 9 upgrades
- Google patches Chrome, beefs up malicious file blocking tech
- Mozilla to launch enterprise Firefox this month with 7X slower pace
- Mozilla persuades Firefox 3.6 users to dump old browser
Read more about Browsers in Computerworld's Browsers Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Browsers White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Browsers Webcasts
