By George Norman - Software News Editor
Added on 04 Aug 2009(543 Views)
The Mozilla Foundation, upon celebrating the fact that the Firefox browser has been downloaded more than 1 billion times since it was first launched, has now released updates for two versions of its browser, mainly Firefox 3.5.2 and Firefox 3.0.13. Just like Firefox 3.5.1 and Firefox 3.0.12, these updates are meant to address a few security vulnerabilities affecting the software – and most of them are critical.

Just to put things in perspective, Mozilla uses a 4-tier rating system for categorizing vulnerabilities: low, moderate, high and critical. A vulnerability is rated as critical only when a person with malicious intent can exploit it to run code and install software on a targeted machine, with no intervention from the targeted user whatsoever. The use just browses and he gets owned. The Firefox 3.5.2 update comes with fixes for a total of 4 critical vulnerabilities (plus one moderate and one low) while the Firefox 3.0.13 update comes with fixes for a total of 2 critical vulnerabilities (plus one moderate).


Firefox Launch Coordinator, Samuel Sidler , comments: “As part of Mozilla’s ongoing stability and security update process, Firefox 3.5.2 and Firefox 3.0.13 are now available for Windows, Mac, and Linux as free downloads. We strongly recommend that all Firefox users upgrade to this latest release. If you already have Firefox 3.5 or Firefox 3, you will receive an automated update notification within 24 to 48 hours. This update can also be applied manually by selecting “Check for Updates…” from the Help menu.”

The security content of the Firefox 3.5.2 update (the bold ones are critical; click the link for additional details):

MFSA 2009-46 Chrome privilege escalation due to incorrectly cached wrapper
MFSA 2009-45 Crashes with evidence of memory corruption (rv:1.9.1.2/1.9.0.13)
MFSA 2009-44 Location bar and SSL indicator spoofing via window.open() on invalid URL
MFSA 2009-43 Heap overflow in certificate regexp parsing
MFSA 2009-42 Compromise of SSL-protected communication
MFSA 2009-38 Data corruption with SOCKS5 reply containing DNS name longer than 15 characters

The security content of the Firefox 3.0.13 update (the bold ones are critical; click the link for additional details):

MFSA 2009-44 Location bar and SSL indicator spoofing via window.open() on invalid URL
MFSA 2009-43 Heap overflow in certificate regexp parsing
MFSA 2009-42 Compromise of SSL-protected communication

On top of the security fixes, the Firefox 3.5.2 update comes with one additional new feature: images with ICC profiles are now properly displayed on all monitors.

If you would like to get Firefox 3.5.2, a download location is available here.
If you would like to get Firefox 3.0.13, a download location is available here.





Don't forget to:

RSS


Tags: Mozilla, Update, Security, Firefox 3.0.13, Firefox 3.5.2

Link to this article:



Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Software News
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
New Labs Feature for Gmail: Green Robot!
The software developers at Google have announced the release of a new Gmail Labs offering called Green Robot! This new offering is meant to improve the Gmail Chat user experience by letting the ...
20 Nov 2009
Opera Mobile 10 Beta for Windows Mobile Is Out Also
Opera Software, the company that we all know for making the innovative and feature rich Opera web browser, has released Opera Mobile 10 Beta for Windows Mobile-powered devices. This release follows in the...
19 Nov 2009
Beta Testing is Over, Stable Version of Trillian for iPhone Released
The focus so far has been on desktop version of this multiprotocol instant messaging software application, Trillian Astra (version 4.1). Today is time to switch focus away from the desktop version and onto something a bit more...
19 Nov 2009
Recommended Tools

Top Downloads