News

Firefox 3.0.8 Released, Critical Security Bugs Fixed

Mozilla rolled out security updates for Firefox after the Web browser was hacked during a contest two weeks ago at a software security convention in Vancouver.

The updates address two separate vulnerabilities in Mozilla Firefox browser versions 3.0.x. Users can get them through "Check For Updates" in the Help menu of the browser, according to the Mozilla Links blog. However, users can also download the latest version of the browser, Firefox 3.0.8, which addresses those vulnerabilities and arrives one week early.

One of the vulnerabilities patched was a proof-of-concept memory corruption bug associated with XSL parsing. This so-called crashing bug was discovered last week by an Italian hacker.

The second vulnerability that Mozilla patched was found by a hacker calling himself Nils. He won $15,000 at the CanSecWest Pwn2Own competition by hacking into three fully patched browsers. Nils first hacked into Internet Explorer 8, finding DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization) bugs that Microsoft since has said are fixed. He also took down Apple's Safari browser, according to this account.

Nils is a 25-year-old computer science student from Germany who would only give his first name during the event. He explained why he was able to hack the Firefox browser, indicating that the "XUL tree method _moveToEdgeShift was in some cases triggering garbage collection routines on objects which were still in use."

This bug caused Firefox to crash. It can allow an attacker the ability to run code on a victim's computer if the user is lured to a Web site laden with ready-to-deploy exploits.

In issuing the updates, Mozilla rated both vulnerabilities as "critical," Mozilla's highest severity rating. Mozilla also indicated that both bugs can also be addressed by disabling JavaScript in the Firefox browser.

About the Author

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

comments powered by Disqus

Featured

  • VS Code 1.125 Adds Copilot Spend Meter After Billing Shock

    VS Code 1.125 adds in-editor visibility into additional Copilot budget usage as GitHub's AI-credit billing model continues to draw developer scrutiny.

  • TypeScript 7.0 RC Moves Microsoft's Go Rewrite Into the Mainline Compiler

    Microsoft's Go-based TypeScript rewrite has reached Release Candidate status, moving from a separate native-preview package into the regular TypeScript npm package while leaving some ecosystem-facing API work for TypeScript 7.1 or later.

  • Microsoft Highlights Visual Studio Live! Event Lineup and Longtime Developer Community Role

    A Microsoft MVP Blog post on Visual Studio Live!'s longevity arrives as the 2026 conference series continues with upcoming stops at Microsoft HQ, San Diego and Orlando.

  • Using Local AI to Cut Copilot Usage-Based Billing Shock

    After being gobsmacked by the new billing plan using almost all my monthly credits in one or two days, I tried pushing some Copilot-style coding work onto local models in VS Code. What I found was less "free AI" and more "pick your pain": cloud charges on one side, heavy local resource use and long waits on the other.

Subscribe on YouTube