Portal IT :: News, download, directory


Search: Friday 4 July 2008









Add to Google Add to My Yahoo!


  Add to Favorites   Set Home Page





« july 2008
s m t w t f s
29 30 1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31 1 2
3 4 5 6 7 8 9







Firefox New Version Fixes Javascript Bug
Published on Security  |  April 17, 2008, 12:23

Mozilla has released a new update for its Firefox browser, thus plugging a critical vulnerability reported recently.

The Javascript vulnerability was reported in version 2.0.0.13, with previous version tagged as “possibly affected” as well. THe company advises Firefox users to upgrade to version 2.0.0.14.

According to Mozilla's advisory, “some users experienced crashes during JavaScript garbage collection. This is being fixed primarily to address stability concerns. We have no demonstration that this particular crash is exploitable but are issuing this advisory because some crashes of this type have been shown to be exploitable in the past.”

Basically, an attacker could've exploited this flaw with the help of a specially-crafted Javascript code. Successful exploitation would've allowed the attacker to run arbitrary code on the infected machine.

Mozilla notes that Thunderbird could also feature the same vulnerability, given the fact that it shares the browser engine with Firefox. The vulnerability can be exploited only if the user chose to enable JavaScript in mail. JavaScript is disabled by default in Thunderbird.




Rate this       Low   High
Curent Rating: 3.0/5 by 7 users
 Print       Email      IM 




 
More Security News
 
Daily News Alert

 
Advertising
 
Top Rated Security News This Month