The Register® — Biting the hand that feeds IT

Feeds

Firefox update fixes bug brace

Booby trap link bug defused

Agentless Backup is Not a Myth

Mozilla has pushed out a new version of Firefox that fixes a brace of security bugs, barely a fortnight after its last update.

Firefox version 2.0.0.6 addresses a critical vulnerability that means unescaped URIs (uniform resource identifiers) are passed to external programs. The serious security flaw, discovered by security researchers last week, created a means for hackers to install malware on a Windows PC simply by convincing potential marks to click on a doctored link.

The update also fixes a less serious privilege escalation vulnerability involving Firefox add-ons.

The release - available in Mac, Windows, and Linux flavours - will be automatically pushed out to users within the next two days. Mozilla's release notes can be found here.

Users of Thunderbird, Firefox's email client, and Mozilla's SeaMonkey suite also need to upgrade as a result of the same bugs to versions 2.0.0.6 and 1.1.4, respectively.

The update is the second from Mozilla in two weeks. Firefox version 2.0.0.5, the previous update, fixed a number of memory corruption and privilege escalation flaws, including a high-profile bug involving launching Firefox from Internet Explorer. ®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments

@ Andy Bright

This comment stream follows the same route as normal.

1. Article points out that a Non-MS product needs an update.

2. Troll pipes up that MS makes a better product (usually includes a ref to fanboy - choose your favourite pretentious spelling).

3. Someone points out that there is nothing superior about said MS product.

4. That someone is automatically a fanboy.

Is that what you mean by “the same thing happening”? Yes it is tedious that every time something non-MS is criticised (however slight) then an MS supporter is there to put the boot in early.

0
0

Odd isn't it

And the same thing happens if anyone has the temerity to report on Fanboiy software in general is patched.

You can't even mention that Firefox, Mac OS or Linux (all of which I use in various capacities) has a security update without muppets feeling the need to point out IE and Windows appear to require more and that they often take months too long to be released.

We know this already - stop bleating pathetic defensive blather just because someone has pointed out it's impossible to write perfect software..

The article let anyone, who for some strange reason wasn't automatically updated by Firefox itself, know there was a fix available. Why is that a problem? Why does anything produced by Microsoft even need to be brought up?

0
0

Re: wake up

As long as you filthbags keep visiting those nasty websites for free warez and a quick peek at Paris's snizz. Then the hackers will always have a avenue to deliver their code.

---

Actually, no.

Firefox with NoScript perfectly handles all the porn sites that none of us ever visits.

Video of Paris anyone?

0
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?