The Register® — Biting the hand that feeds IT

Unholy trio menace Firefox

Critical update for Mozilla and Firefox

Free whitepaper – Securing your online data transfer with SSL

The Mozilla Foundation has released updated versions of its popular Firefox (version 1.0.3) and Mozilla (version 1.7.7) web browsers to correct a number of recently discovered security flaws. The updates fix a trio of critical vulnerabilities, two of which have become the subject of proof-of-concept hacker exploits.

A bug that allows hackers to inject JavaScript code in link tags supporting "favicons" and a Mozilla-specific flaw which allows the execution of arbitrary code remotely via the Firefox side bar both pose a severe risk after they were recently coded up in script-kiddie friendly exploits. A third critical security bug - affecting versions of the browsers prior to Firefox 1.0.3 and Mozilla 1.7.7 - involves privilege escalation via DOM (Document Object Model) property overrides.

Firefox 1.0.3 and Mozilla 1.7.7 also addresses six lesser security risks as described by Secunia here. Users of the popular browsers are strongly urged to apply the appropriate update. ®

Related stories

Firefox dusted down with security upgrade
Browser bugs sprout eternal
Drive-by Trojans exploit browser flaws

Free whitepaper – The starter PKI program

Don’t Miss

GoogleGoogle cloud told to encrypt itself

Updated R in RSA wants s in https

thumbs down teaser 75Buggy 'smart meters' open door to power-grid botnet

Grid-burrowing worm only the beginning

Flag ChinaChinese firm hits back at cyberspy claims

Exclusive Huawei welcomes UK.gov backdoor probe

BlockMaster SafeStickBlockMaster SafeStick hardware-encrypted USB drive

Review Tough enough?