Firefox 6 patches 10 dangerous security holes
Summary: The vulnerabilities are serious enough to allow an attacker to launch harmful code and install software, requiring no user interaction beyond normal browsing.
Mozilla has shipped a critical Firefox update to fix at least 10 security vulnerabilities, some serious enough to expose web surfers to drive-by download attacks.
According to an advisory from the open-source group, 8 of the 10 vulnerabilities are rated "critical," meaning that they can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.
Here's a glimpse of the critical issues:
Mozilla identified and fixed several memory safety bugs in the browser engine used in Firefox 4, Firefox 5 and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
These include a WebGL crash, a JavaScript crash, a crash in the Ogg reader, memory safety issues and unsigned scripts. These all affected Firefox 4 and 5.
Mozilla also credited researcher Michael Jordon of Context IS with reporting a pair of critical issues -- that an overly long shader program could cause a buffer overrun and crash in a string class used to store the shader source code; and a potentially exploitable heap overflow in the ANGLE library used by Mozilla's WebGL implementation.
Some additional security problems fixed:
- Security researcher regenrecht reported via TippingPoint's Zero Day Initiative that a SVG text manipulation routine contained a dangling pointer vulnerability.
- Mike Cardwell reported that Content Security Policy violation reports failed to strip out proxy authorization credentials from the list of request headers. Daniel Veditz reported that redirecting to a website with Content Security Policy resulted in the incorrect resolution of hosts in the constructed policy.
- nasalislarvatus3000 reported that when using Windows D2D hardware acceleration, image data from one domain could be inserted into a canvas and read by a different domain.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
RE: Firefox 6 patches 10 dangerous security holes
What are you talking about?
Big deal.
That is you
Enterprise won't do it this way. It has its version control policy.
Well maybe they need to re-think that
Besides, Cylon didn't mention enterprise. He mentioned himself.
Rather, they will rethink using Firefox
Really, they won't use Firefox in the Enterprise anyway, since there is no MSI managed installer to use with Group Policy...
If ninite can mange installtion (firefox included)
I am sure system administrators can find a way to deploy it.
When our first .net application was deployed in a big enterprise, they don't even have .net framework there (9 years ago). They just packed all dlls and deployed it. When .net framework finally got in the system, our application was broken. They have to uninstall old package, install framework, then install application again.
Anyway, in enterprise, especially in goverment, version control is no small issue. Ask anyone about TRM (Technology Refernce Model), that is guidance for software/hardware approval processes.
I guess firefox is not for enterprise...
Ignore him.....
Cylon Centurion is a Microsoft shill and troll. He thinks that Microsoft Idiot Explorer never had an issue and never had a patch before....Idiot Explorer has more holes in it than swiss cheese.
RE: Firefox 6 patches 10 dangerous security holes
Big deal? You consider broken addons not to be? Mozilla is pretty much telling me to either suffer broken addons or suffer security holes which won't be patched, unless I upgrade. That's bullshit. As a heavy Firefox user, that is total bullshit.
RE: Firefox 6 patches 10 dangerous security holes
Man! This is annoying!
RE: Firefox 6 patches 10 dangerous security holes
RE: Firefox 6 patches 10 dangerous security holes
Yes, I have a broken addon. Stylish doesn't work. I use Stylish to correct a few quirks with the UI that I find annoying.
RE: Firefox 6 patches 10 dangerous security holes
Besides Stylish Custom 0.7.7 works just fine. Try that.
RE: Firefox 6 patches 10 dangerous security holes
Just having one broken addon is too many. Now, tell me again, why Mozilla is playing this numbers games again?
RE: Firefox 6 patches 10 dangerous security holes
RE: Firefox 6 patches 10 dangerous security holes
RE: Firefox 6 patches 10 dangerous security holes
What other Add Ons did they break this time? Who knows?
RE: Firefox 6 patches 10 dangerous security holes
Plus, how was my comment shilling for MSFT?
RE: Firefox 6 patches 10 dangerous security holes
RE: Firefox 6 patches 10 dangerous security holes
See above.
RE: Firefox 6 patches 10 dangerous security holes
If you can't keep up with it then go back to IE9 and have sh!tty pop up ads and Flash animations galore.