Original URL: http://www.theregister.co.uk/2008/09/24/firefox_update/
Firefox update fixes critical bug brace
Just off the production line
Mozilla published a new version of its Firefox web browser on Tuesday that fixes five security vulnerabilities, two of which it rates as critical.
Firefox version 3.0.2 fixes a memory corruption bug and a separate critical bug involving privilege escalation and the XPCnativeWrapper component of the browser. Both create possible mechanisms for hackers to inject hostile code into vulnerable systems using rigged websites, or perform similar tricks.
The same two critical bugs are fixed in Firefox 188.8.131.52, for those still using the earlier version of the browser. There's no evidence that either critical flaw has been exploited by hackers but prudence would steer towards early patching. Judging from past experience automatic updates from Mozilla will appear in about a day or so.
The updates also fix three lesser flaws - two of which are rated as moderate and one of which earns a low risk rating.