Home > Security News > Mozilla patches 11 Firefox security flaws, JavaScript errors
Security News:
EMAIL THIS

Mozilla patches 11 Firefox security flaws, JavaScript errors

By Robert Westervelt, News Editor
12 Jun 2009 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Mozilla Foundation updated its Firefox browser late Thursday, deploying fixes to 11 vulnerabilities, including six critical flaws, mostly JavaScript related, which could be used by an attacker to run arbitrary code and gain access to system files.

Firefox 3.0.11 patches critical memory corruption errors, a race condition and a JavaScript chrome privilege escalation. Most user browsers will be updated automatically to the latest version.

In its list of advisories, Mozilla said the JavaScript chrome privilege escalation allows scripts from page content to run with elevated privileges. Several memory corruption errors were fixed, stabilizing the browser engine.
Recent FireFox updates:
FireFox 3.0.10 - Mozilla patches a dozen Firefox vulnerabilities: The flaws expose users to URL spoofing, cross-site scripting, code injection and code execution attacks.

FireFox 3.0.9 - Firefox update addresses several security flaws Mozilla's release repairs a critical vulnerability that could have been exploited to run arbitrary code.

FireFox 3.0.8 -
Firefox update blocks proof-of-concept code: Mozilla updated Firefox to repair several flaws, including a critical zero-day flaw.

"Some of these crashes showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code," Mozilla said.

Mozilla said a race condition existed, allowing an attacker to write to freed memory under a certain condition if a person navigated away from a webpage during the loading of a Java applet. The browser maker also repaired a condition in which event listeners may be executed within the wrong JavaScript context.

"An attacker could potentially use this vulnerability to have a malicious event handler execute arbitrary JavaScript with chrome privileges," Mozilla said. Less critical vulnerabilities included:



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts