News

Firefox 3.0.8 Released, Critical Security Bugs Fixed

Mozilla rolled out security updates for Firefox after the Web browser was hacked during a contest two weeks ago at a software security convention in Vancouver.

The updates address two separate vulnerabilities in Mozilla Firefox browser versions 3.0.x. Users can get them through "Check For Updates" in the Help menu of the browser, according to the Mozilla Links blog. However, users can also download the latest version of the browser, Firefox 3.0.8, which addresses those vulnerabilities and arrives one week early.

One of the vulnerabilities patched was a proof-of-concept memory corruption bug associated with XSL parsing. This so-called crashing bug was discovered last week by an Italian hacker.

The second vulnerability that Mozilla patched was found by a hacker calling himself Nils. He won $15,000 at the CanSecWest Pwn2Own competition by hacking into three fully patched browsers. Nils first hacked into Internet Explorer 8, finding DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization) bugs that Microsoft since has said are fixed. He also took down Apple's Safari browser, according to this account.

Nils is a 25-year-old computer science student from Germany who would only give his first name during the event. He explained why he was able to hack the Firefox browser, indicating that the "XUL tree method _moveToEdgeShift was in some cases triggering garbage collection routines on objects which were still in use."

This bug caused Firefox to crash. It can allow an attacker the ability to run code on a victim's computer if the user is lured to a Web site laden with ready-to-deploy exploits.

In issuing the updates, Mozilla rated both vulnerabilities as "critical," Mozilla's highest severity rating. Mozilla also indicated that both bugs can also be addressed by disabling JavaScript in the Firefox browser.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

comments powered by Disqus

Featured

  • Another Report Weighs In on GitHub Copilot Dev Productivity: 👎

    Several reports have answered "yes" to the question of whether GitHub Copilot improves developer productivity. A new one says "no."

  • Logistic Regression with Batch SGD Training and Weight Decay Using C#

    Dr. James McCaffrey from Microsoft Research presents a complete end-to-end program that explains how to perform binary classification (predicting a variable with two possible discrete values) using logistic regression, where the prediction model is trained using batch stochastic gradient descent with weight decay.

  • Dev Asks, and 7 Years Later Python in VS Code Delivers Django Unit Test Support

    "We are excited to announce support for one of our most requested features: you can now discover and run Django unit tests through the Test Explorer!"

  • OData Finally Ditches Old .NET Framework

    "The most disruptive change we are making in this release is dropping support for .NET Framework."

Subscribe on YouTube