Home › News › Industry News
Mozilla patches three Firefox security vulnerabilities
As promised a few days ago, the Mozilla developers this morning released Firefox version 2.0.0.10. The update is the ninth security update to the open-source browser this year and addresses three high impact security vulnerabilities, including a cross-site scripting flaw in the jar: URI scheme, which may allow an attacker to steal private information – a published proof-of-concept demonstrates stealing the Gmail contact list of users logged-in to the service.
Firefox 2.0.0.10 also fixes three memory corruption bugs, which could be exploited to crash systems and inject code, and a cross-site request forgery vulnerability that could allow an attacker to generate a fake HTTP Referer header by exploiting a timing condition when setting the window.location property. Automatic update screens should now be popping up for Firefox users, so you can either use the auto update function within the browser or head to our download section to get the latest version now.
Firefox 2.0.0.10 also fixes three memory corruption bugs, which could be exploited to crash systems and inject code, and a cross-site request forgery vulnerability that could allow an attacker to generate a fake HTTP Referer header by exploiting a timing condition when setting the window.location property. Automatic update screens should now be popping up for Firefox users, so you can either use the auto update function within the browser or head to our download section to get the latest version now.
Related Stories
Most Popular
| Trending | Featured |
-
iOS 5.1.1 untethered jailbreak tool released, supports 4S, iPad 3
-
After five days, Facebook ranks as worst IPO flop of the decade
-
Rumor: Windows 8 RC will launch June 1, will ship with Adobe Flash
-
Rumor: AMD "Piledriver" FX CPU production to begin Q3 2012
-
Diablo III becomes the fastest-selling PC game in history
Editors' Storage Picks
Subscribe to TechSpot
Get free exclusive content, learn about new features and tech breaking news.