Mozilla fixes 'critical' flaws

By Joris Evers, CNET News.com
Thursday, November 09, 2006 10:37 AM

Mozilla has released updates for its Firefox browser, Thunderbird e-mail application and the SeaMonkey application suite to fix "critical" security vulnerabilities.

The vulnerabilities affect 1.5 versions of Firefox and Thunderbird as well as version 1 of the SeaMonkey suite, Mozilla said in its security advisories. The bugs do not affect Firefox 2.0, the latest version of the browser released late last month.

Security monitoring companies Secunia and the French Security Incident Response Team, or FrSIRT, deem the issues "highly critical" and critical," respectively. People who use vulnerable versions of the Mozilla products are urged to upgrade to the fixed versions, both companies said.

Mozilla has fixed a number of bugs that could cause its products to crash or, in some cases, be exploited to hijack a PC, it said in an advisory. Other problems that have been repaired include a flaw that could be abused to run malicious JavaScript and a vulnerability that could let miscreants fake digital signatures, Mozilla said.

"The security vulnerabilities could be exploited by malicious people to bypass security restrictions, conduct cross-site scripting attacks and potentially compromise a vulnerable system," Secunia said in its alert.

Mozilla plans to support Firefox 1.5 until October 2007, one year after it shipped Firefox 2. The security flaws are fixed in Firefox 1.5.0.8, Thunderbird 1.5.0.8 and SeaMonkey 1.0.6. The previous Firefox security update was released in September.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Don't worry Mozilla will repair the bug most faster from all browsers, becouse is most faster! Did you know that you can significantly speed up Firefox more yet? You can find manual how to easily speed up Firefox over here: www.mozila.pl...
Posted by melon on Thursday, November 09 2006 05:42 PM


Tech Jobs Now!

Search for your ideal tech job:

Hands-on programming: Extract plain text from documents with Syncfusion's components

Web Development

Justin James recently tried Syncfusion's Essential DocIO and Essential PDF to help him extract text from documents he downloaded from the Internet. Here's the code he wrote to get the plain text.


Read more »



Will technology divide us further?

Blog thumbnail

So I finally watched 2012 over the weekend, but the film left me feeling extremely agitated.

The possibility that the world may meet its watery end in three years didn't..... by Eileen Yu

Read more »

Tags

  1. advertisement
  2. blog
  3. facebook
  4. google inc.
  5. internet
  6. internet advertising
  7. microsoft corp.
  8. network
  9. revenue
  10. search
  11. social networking
  12. software
  13. u.s.
  14. web
  15. web 2.0
  16. web browser
  17. web browsers
  18. web services
  19. web sites
  20. yahoo! inc.