The Register® — Biting the hand that feeds IT

Feeds

Firefox 3.5.4 fixes critical memory flaws

Vulns found all alone in moonlight

What you need to know about cloud backup

Mozilla trotted out Firefox 3.5.4 yesterday, which patches 16 vulns - 11 of which were critical bugs.

The browser maker said the 11 critical vulnerabilities were found in a number of components such as the JavaScript and browser engines, the GIF color map parser, the strings-to-number converter, three third party media libraries and web worker calls.

"Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code," said Mozilla.

The open source outfit had been expected to release Firefox 3.5.4 on 21 October, after shooting out a release candidate version of the update early last month.

Meanwhile, a beta of the next iteration of Mozilla's popular browser - Firefox 3.6 - might be squirted out later today.

Mozilla has already pushed the release of that version back several times, however.

Get your hands on the update here.®

Steps to Take Before Choosing a Business Continuity Partner

Latest Comments

oh dear, same on, same old.

fire fox, memory issue u say, how unusual

0
0

3.0.15 ALSO Got Issued

For those who are still at 3.0.x (who have not upgraded to 3.5 yet for reasons such as needed plug-ins not being issued for 3.5 yet) 3.0.15 was issued at the same time as 3.5.4 was. I have not compared the two fix lists but I think that at least some are on both lists due to being newly discovered exploits.

0
0

Strange...

I'm running Firefox on my laptop at home, it's never crashed, always loads up within seconds and never slows down my system, and I've only had one update in about a month.

Still, Better not say that, as it doesn't follow the Firefox bashing trend.

0
0

More from The Register

Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Apple: iOS7 dayglo Barbie makeover is UNFINISHED - report
Plus: You don't like the icons? Blame marketing
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry
Apple at WWDC: Sleek new iOS, death of the big cats, pint-sized Mac Pro
CEO Cook: 'The biggest change to iOS since the introduction of the iPhone'
Chrome and Firefox are planet-wreckers, IE cuddles dolphins
Microsoft-commissioned study finds IE sucks less power than rival browsers