Mozilla Patches Holes in Firefox

Earlier this week, Mozilla released the latest revision of Firefox, with the snappy label version 2.0.0.10. The latest update patches three recently reported vulnerabilities.

Two of the potential security holes involved cross-site scripting issues. Hackers can use these vulnerabilities to steal personal information while visiting certain sites. Exploiting the first cross-site vulnerability, an attacker could create a fake HTTP refer header when setting the window location property. There's a timing issue involved with this process that permits the hack. The other cross-site loophole comes into play with Web sites loading ZIP archives.

The third vulnerability involves memory corruption, some of which could be used to insert random or malicious code.

Mozilla is pushing the update to all current Firefox users, so that should get the word out as soon as possible. Check out the Mozilla Web site for more on these fixes.

Mozilla seems to have its own Patch Tuesday. And I thought Mondays were bad news. Are you using Firefox? Have you found any of these vulnerabilities? How about IE? Found any loopholes on your own there? Log in and let me know at llow@redmondmag.com.

Posted by Lafe Low on 11/28/2007 at 1:23 PM


Featured

  • Azure Backup for SQL Server Now Commercially Available

    Microsoft on Monday announced that Azure Backup for SQL Server had reached "general availability" status, meaning it's deemed ready for production-environment use.

  • Insights for MyAnalytics Getting Switched On for Office 365 Users This Month

    Microsoft is planning to activate "Insights for MyAnalytics" sometime late this month for most Office 365 users, but the ability of organizations to manage this feature won't be available until possibly mid-May.

  • SharePoint Framework 1.8 Now Generally Available

    Microsoft this week announced that SharePoint Framework 1.8 had reached "general availability" status, although some features are still at the preview stage.

  • How To Create Office 365 User Accounts in Bulk

    Manual account creation can be tedious, time-consuming and prone to human error, especially if you have more than a handful of Office 365 users to set up. Brien shows you a better way.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.