Advertisement
Promo

Security threats Toolkit

Mozilla: Patch Firefox now

Richard Thurston ZDNet.co.uk

Published: 20 Dec 2006 13:13 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Firefox users have been urged to update their browser immediately after Mozilla, the organisation behind the popular browser, said it had fixed eight vulnerabilities in Firefox 2.0.

Mozilla said five of the eight vulnerabilities were 'critical', meaning an attacker could exploit the weaknesses to run malicious code on the compromised machine. Seven vulnerability updates have been issued for the previous version of Firefox, version 1.5, of which five are rated as critical. Mozilla also urged users of its Thunderbird email application to download several security updates.

The updated version was made available on Tuesday evening. It can be downloaded from Mozilla's website. Firefox users who have set their browser to receive automatic updates will be notified or sent the update, depending on their preferences.

The updates to Firefox 2.0 are the first since its release in late October. They cover flaws in memory corruption, and the way the browser executes RSS, Javascript and CSS code.

Version 1.5 has already seen a whole raft of updates, including the patching of other critical vulnerabilities in November.

According to Mozilla developers, the Firefox updates will work with Vista, which was released to businesses three weeks ago.

Security research organisation Secunia rated the Mozilla flaws as 'highly critical' and described the threats in detail on its site.

Tristan Nitot, president of Mozilla Europe, confirmed that Mozilla plans to drop support for Firefox 1.5 on 24 April, 2007, not October 2007 as previously reported. "We are consistent with our approach, which is to support a version, in this case 1.5.0.x, for six months after the following version, in this case Firefox 2," Nitot said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
348 out of 363 people found this useful


Full Talkback thread

1 comment

  1. FF auto updated welshtroll

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

Post a comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters