Australian IT JOBS : Sydney IT jobs, UNIX jobs, Linux jobs, Java jobs, ASP jobs Linux.conf.au Linux.conf.au
Technology news and Jobs arrow Information Technology News arrow Firefox 2.0.0.10 patches high-impact security flaws
Firefox 2.0.0.10 patches high-impact security flaws PDF Print E-mail
Written by Stephen Withers   
Wednesday, 28 November 2007
The latest release of the popular Firefox open source web browser fixes a trio of security flaws described by Mozilla as being of high impact.

The delivery of the update follows a 'test day' last Friday that was intended to shake out any issues that remained in the release candidate.

Firefox 2.0.0.10 restricts the jar: URI scheme to files delivered with a MIME type of application/java-archive or application/x-jar to avoid trusting non-Java content that could be used in cross-site scripting attacks. The flaw had been exploited to steal Gmail contact lists.

Another specific issue corrected by the update blocks a way of carrying out cross-site request forgery attack on sites by generating a fake HTTP Referrer header.

Also patched are three bugs that had been shown to cause memory corruption in some circumstances and that could potentially be exploited to execute arbitrary code.

No other changes were made to the application.

The update is being pushed out to Firefox users, or the new version can be downloaded from Mozilla.com.



Get stories like this delivered daily - FREE - subscribe now
When you subscribe get a 12 months license for LiveProject
Valued at $99 USD


LiveWire - Desktop alerts Download the FREE iTWire desktop alert widget LiveWire - Desktop alerts


Del.icio.us!
 
< Prev   Next >

Latest jobs

Contact , Register , Advertise with iTWire , Links , Register , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging
Industry Releases , Submit your release now , Start submitting to iTWire , How to post video