Advertisement
Promo

Security threats Toolkit

Mozilla issues 'critical' fixes

Joris Evers CNET News

Published: 09 Nov 2006 10:09 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Mozilla has released updates for its Firefox browser, Thunderbird email application and the SeaMonkey application suite to fix "critical" security vulnerabilities.

The vulnerabilities affect 1.5 versions of Firefox and Thunderbird as well as version 1 of the SeaMonkey suite, Mozilla said in its security advisories. The bugs do not affect Firefox 2.0, the latest version of the browser released late last month.

Security monitoring companies Secunia and the French Security Incident Response Team, or FrSIRT, deem the issues "highly critical" and "critical", respectively. People who use vulnerable versions of the Mozilla products are urged to upgrade to the fixed versions, both companies said.

Mozilla has fixed a number of bugs that could cause its products to crash or, in some cases, be exploited to hijack a PC, it said in an advisory. Other problems that have been repaired include a flaw that could be abused to run malicious JavaScript and a vulnerability that could let miscreants fake digital signatures, Mozilla said.

"The security vulnerabilities could be exploited by malicious people to bypass security restrictions, conduct cross-site scripting attacks and potentially compromise a vulnerable system," Secunia said in its alert.

Mozilla plans to support Firefox 1.5 until October 2007, one year after it shipped Firefox 2. The security flaws are fixed in Firefox 1.5.0.8, Thunderbird 1.5.0.8 and SeaMonkey 1.0.6. The previous Firefox security update was released in September.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
549 out of 648 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters