Skip to navigation
Latest News

Firefox update squashes 11 bugs

By Stuart Turton

Posted on 12 Jun 2009 at 11:10

Mozilla's latest update to the Firefox browser brings with it 11 security fixes, including four for critical vulnerabilities.

Critical represents the Foundation's highest security level, and the majority of the bugs would have allowed attackers to run malware on affected computers.

Among the most serious of the holes plugged by the update was a flaw in the browser's JavaScript event handler allowing attackers to execute arbitrary code with local chrome privileges.

The patch also addresses another privilege escalation bug that allowed hackers to hijack chrome objects and run malicious code when visiting specific websites.

Mozilla also noted a race condition bug that popped up when deleting Java objects, giving attackers the ability to execute code held in the freed memory.

Also on the bug list is one fix ranked as high importance. This addresses a flaw in SSL handling that would have allowed an attacker to intercept CONNECT requests and run Javascript on the affected machine while pretending it had come from a secure site.

Interestingly, this bug was actually picked up by Microsoft back in January and passed along to the development team. The problem also affects SeaMonkey and Thunderbird.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

Most Commented News Stories
More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.