Firefox – Mozilla confirms critical bug – Firefox to the Rescue
Posted • March 24, 2010 • 1 Comment
Mozilla confirms a critical vulnerability in the latest version of Firefox, and promised to plug the hole by the end of the month.
Firefox 3.6 launched in January has a security hole. Shall we call it a bug or a feature?
Mozilla states that it would be patched in version 3.6.2, currently which should be released March 30th.
This patch won’t be added to Firefox before the Pwn2Own browser hacking challenge. The researchers won’t be allowed to use this particular flaw, according to the contest’s organizer.
The Pwn2Own hacking contest started today! They will call it a feature.
(Post from Search Engine Optimizician.)
This bug was disclosed by Evgeny Legerov, a Russian researcher, about a month ago in a message posted on a forum.
Mozilla confirms critical Firefox bug
By Gregg Keizer
Legerov did not publish attack code, and initially refused to provide details to Mozilla, according to a March 4 entry he posted on his blog. “I’ve ignored e-mails … from Mozilla, please do not waste my and your time anymore,” Legerov wrote. The blog has since been deleted, but is still available via Google’s cache.
Mozilla yesterday said Legerov had eventually sent them “sufficient details to reproduce and analyze the issue.”
According to Mozilla:
To clarify, as originally claimed this issue affects Firefox 3.6 only and not any earlier versions. Thunderbird and SeaMonkey are based on earlier versions of the browser engine and are not affected. People testing “3.7″ development builds should upgrade to 3.7 alpha 3 or the latest nightly build to ensure they have this fix.
Mozilla urges Firefox users to download Release Candidate builds of Firefox 3.6.2 which contains the fix from the Beta fix download files here.
We will call it a bug.
Never Mind Firefox 3.6.2 was released ahead of sehedule:
Mozilla has accelerated its timetable and released Firefox 3.6.2 ahead of schedule. This release contains a number of security fixes, including a fix to Secunia Advisory SA38608 which was previously discussed on this blog when we were first made aware of and were then able to confirm the issue.
For additional information please see Mozilla Foundation’s Security Advisory MFSA-10-08 as well as the Firefox 3.6.2 Release Notes. We urge users to promptly update to this release by selecting “Check for Updates…” from the “Help” menu, or by visiting https://www.mozilla.com/ for a free download.
Late,
Gary Pool SEO
Terms related to this post:
Comments
One Response to “Firefox – Mozilla confirms critical bug – Firefox to the Rescue”
ShareThis












March 24th, 2010 @ 5:43 pm
[...] This post was mentioned on Twitter by Gary Pool, Vaidhyanathan SEO. Firefox – Mozilla confirms critical bug – Firefox to the Rescue http://bit.ly/cpQiH5 [...]