Feeds

Firefox update fixes four critical flaws

Laggard 2.x users urged to upgrade

Boost IT visibility and business value

Users of Firefox need to update their browser software again following the publication of patches by Mozilla on Wednesday.

Both supported versions of Firefox need patching but the 2.x version of the popular open source browser is most in need of a retool. Firefox 2.0.0.18 addresses 11 security vulnerabilities, six of which are classified as critical. Meanwhile, on the other track, Firefox 3.0.4 lances nine security vulnerabilities, four of which are critical.

The critical flaws in Firefox 3.x cover a vulnerability in the session restore feature that could allow cross-site scripting attacks and a separate memory corruption flaw as well as code injection risks involving the nsFrameManager and http-index-format parser of the browser. Mozilla's advisory explains the bugs in greater depth here.

Firefox 3.0.4 also fixes a slew of stability and performance glitches.

Mozilla's developers urge those left behind on the Firefox 2.x release to upgrade to Firefox 3.x, warning that it will stop issuing stability and security patches for the older release next month.

The SeaMonkey internet application suite evolved from the same code base as Mozilla's Application Suite and needs patching against the same 11 flaws as Firefox 2.x. Seamonkey, a community-driven project separate from Mozilla since, advises users to upgrade to Seamonkey 1.1.13. ®

Build a business case: developing custom apps

More from The Register

next story
The Return of BSOD: Does ANYONE trust Microsoft patches?
Sysadmins, you're either fighting fires or seen as incompetents now
Linux turns 23 and Linus Torvalds celebrates as only he can
No, not with swearing, but by controlling the release cycle
China hopes home-grown OS will oust Microsoft
Doesn't much like Apple or Google, either
Sin COS to tan Windows? Chinese operating system to debut in autumn – report
Development alliance working on desktop, mobe software
Apple promises to lift Curse of the Drained iPhone 5 Battery
Have you tried turning it off and...? Never mind, here's a replacement
Why has the web gone to hell? Market chaos and HUMAN NATURE
Tim Berners-Lee isn't happy, but we should be
Eat up Martha! Microsoft slings handwriting recog into OneNote on Android
Freehand input on non-Windows kit for the first time
Linux kernel devs made to finger their dongles before contributing code
Two-factor auth enabled for Kernel.org repositories
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Scale data protection with your virtual environment
To scale at the rate of virtualization growth, data protection solutions need to adopt new capabilities and simplify current features.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?