April 23, 2009 - 2:55am
An updated version of Firefox browser was released on Tuesday by Mozilla, reports the Register. The new pack is meant to address nine security vulnerabilities one of which is the most critical.
The critical flaw addressed by Firefox 3.09 relates to a memory corruption problem. The two "high-risk" flaws involve same-origin violation security bugs. The remnant six flaws are as follows:
• Firefox allows Refresh header to redirect to javascript: URIs
• jar: scheme ignores the content-disposition: header on the inner URI
• POST data sent to wrong site when saving web page with embedded frame
• Malicious search plugins can inject code into arbitrary sites
• XSS hazard using third-party stylesheets and XBL bindings
• URL spoofing with box drawing character
In addition Firefox 3.0.9 also addresses some stability problems such as a problem where a corrupt local database might cause Firefox to "lose" its stored cookies and a flaw that means in-line images might not be displayed when using webmail accounts was also plugged.
The company reported that user systems will be automatically updated to version 3.0.9 within 48 hours. The new version can also be downloaded from the site manually. Firefox version 2.0 is no longer supported.
The critical flaw addressed by Firefox 3.09 relates to a memory corruption problem. The two "high-risk" flaws involve same-origin violation security bugs. The remnant six flaws are as follows:
• Firefox allows Refresh header to redirect to javascript: URIs
• jar: scheme ignores the content-disposition: header on the inner URI
• POST data sent to wrong site when saving web page with embedded frame
• Malicious search plugins can inject code into arbitrary sites
• XSS hazard using third-party stylesheets and XBL bindings
• URL spoofing with box drawing character
In addition Firefox 3.0.9 also addresses some stability problems such as a problem where a corrupt local database might cause Firefox to "lose" its stored cookies and a flaw that means in-line images might not be displayed when using webmail accounts was also plugged.
The company reported that user systems will be automatically updated to version 3.0.9 within 48 hours. The new version can also be downloaded from the site manually. Firefox version 2.0 is no longer supported.