Security:
News ToolsReg Shops |
The Register » Security » Firefox update fixes bug braceBooby trap link bug defusedPublished Tuesday 31st July 2007 11:17 GMT Mozilla has pushed out a new version of Firefox that fixes a brace of security bugs, barely a fortnight after its last update. Firefox version 2.0.0.6 addresses a critical vulnerability that means unescaped URIs (uniform resource identifiers) are passed to external programs. The serious security flaw, discovered by security researchers last week, created a means for hackers to install malware on a Windows PC simply by convincing potential marks to click on a doctored link. The update also fixes a less serious privilege escalation vulnerability involving Firefox add-ons. The release - available in Mac, Windows, and Linux flavours - will be automatically pushed out to users within the next two days. Mozilla's release notes can be found here. Users of Thunderbird, Firefox's email client, and Mozilla's SeaMonkey suite also need to upgrade as a result of the same bugs to versions 2.0.0.6 and 1.1.4, respectively. The update is the second from Mozilla in two weeks. Firefox version 2.0.0.5, the previous update, fixed a number of memory corruption and privilege escalation flaws, including a high-profile bug involving launching Firefox from Internet Explorer. ® 29 comments posted — Comment period finished Gosh they must have a lot of bugsPosted: 11:24 31st July 2007 i.e.7Posted: 11:31 31st July 2007 ffsPosted: 11:33 31st July 2007 Re: IE7Posted: 11:57 31st July 2007 ThxPosted: 12:15 31st July 2007
Track this type of story as a custom Atom/RSS feed or by email.
|
|
Top 20 stories • All The Week’s Headlines • Archive • Search