Subpages

Find us on

Categories

Recent Spotlights

Poll

User: Password: Forget Password? | Register
 
Mozilla Firefox 3.0.8 is here
 

Windows X's Live recommends:
Before and after making any changes to your system: Check Windows for registry errors.
TuneUp Utilities: Clean up your PC and improve your PCs performance - Try now for free!

This version 3.0.8 of Firefox was expected by early next week but was finally released earlier than expected, therefore, be limited to the correction of security vulnerabilities, two qualified criticism.

One of these vulnerabilities has been reported at the contest by the mysterious Pwn2Own Nils. Mozilla had a priori the time needed to correct this bug being placed under the seal of secrecy by the organizing company TippingPoint. The second bug seemed to against the more urgent to correct because of its public disclosure by its discoverer Guido Landi.

The Italian security researcher follower of full disclosure, a questionable practice, discovered and given all the information needed to run a bug where an XSL stylesheet can be used to crash the browser during processing XSL. An attacker may leverage this crash to execute arbitrary code on a machine under attack.

The bug is called Nils for its type execution of arbitrary code via the object tree of XUL, the language of description of graphical interfaces in Mozilla. If it is specific to Mozilla Firefox, Nils has also discovered and exploited during the Pwn2Own a bug in Internet Explorer 8, which has attracted the attention of the president of Mozilla Europe, who took the opportunity to launch a challenge to Microsoft.

Mozilla has the custom to register false when assessing the safety level of a browser by simply counting the number of vulnerabilities discovered. These are inevitable and Mozilla prefers as a criterion for the time value of responsiveness, a correction and an appropriate deployment of the patch as soon as possible.