Update on Critical Firefox 3.6 Vulnerability Uncovered by Russian Researcher
Late this February we were reporting that Firefox 3.6, the latest and greatest version in the Firefox range, is plagued by a critical security vulnerability - that's the rating given to it by Secunia , Danish company that specializes in providing software for vulnerability management and is best known for tracking the latest security threats and offering info about patches.
The vulnerability in question was discovered by a Russian security expert from Intevydis, company that made it available to their customers - Intevydis, develops the commercial VulnDisco add-on for the Canvas exploit toolkit by vendor Immunity.
According to Intevydis developer Evgeny Legerov, the vulnerability in question is a buffer overflow vulnerability that can be used to remotely take control of the targeted machine. Sounds bad, I know. The good news is that only Firefox 3.6 is affected and only the Windows version – the Mac OS X and Linux versions are fine.
When news of this vulnerability broke out, Mozilla announced that it cannot confirm the vulnerability is genuine as it did not receive any details about it. For example a proof-of-concept or steps to reproduce the vulnerability in question would have been helpful. Furthermore, the security researcher that uncovered the vulnerability, Evgeny Legerov, failed to respond to Mozilla’s requests for more information – until now that is.
About a month after spreading the word that Firefox 3.6 is plagued by a critical security vulnerability, Evgeny Legerov has finally contacted Mozilla.
“Mozilla was contacted by Evgeny Legerov, the security researcher who discovered the bug referenced in the Secunia report, with sufficient details to reproduce and analyze the issue. The vulnerability was determined to be critical and could result in remote code execution by an attacker. The vulnerability has been patched by developers and we are currently undergoing quality assurance testing for the fix. Firefox 3.6.2 is scheduled to be released March 30th and will contain the fix for this issue. As always, we encourage users to apply this update as soon as it is available to ensure a safe browsing experience,” explained Mozilla.
Again, only Firefox 3.6 is affected; previous versions are not affected by this vulnerability. The upcoming Firefox 3.6.2 version is not affected as well – the downside is that for now you can only get a release candidate build of Firefox 3.6.2 – click here.
Tags: Mozilla, Firefox, Firefox 3.6, Security, Intevydis
The vulnerability in question was discovered by a Russian security expert from Intevydis, company that made it available to their customers - Intevydis, develops the commercial VulnDisco add-on for the Canvas exploit toolkit by vendor Immunity.
Advertising
According to Intevydis developer Evgeny Legerov, the vulnerability in question is a buffer overflow vulnerability that can be used to remotely take control of the targeted machine. Sounds bad, I know. The good news is that only Firefox 3.6 is affected and only the Windows version – the Mac OS X and Linux versions are fine.
When news of this vulnerability broke out, Mozilla announced that it cannot confirm the vulnerability is genuine as it did not receive any details about it. For example a proof-of-concept or steps to reproduce the vulnerability in question would have been helpful. Furthermore, the security researcher that uncovered the vulnerability, Evgeny Legerov, failed to respond to Mozilla’s requests for more information – until now that is.
About a month after spreading the word that Firefox 3.6 is plagued by a critical security vulnerability, Evgeny Legerov has finally contacted Mozilla.
“Mozilla was contacted by Evgeny Legerov, the security researcher who discovered the bug referenced in the Secunia report, with sufficient details to reproduce and analyze the issue. The vulnerability was determined to be critical and could result in remote code execution by an attacker. The vulnerability has been patched by developers and we are currently undergoing quality assurance testing for the fix. Firefox 3.6.2 is scheduled to be released March 30th and will contain the fix for this issue. As always, we encourage users to apply this update as soon as it is available to ensure a safe browsing experience,” explained Mozilla.
Again, only Firefox 3.6 is affected; previous versions are not affected by this vulnerability. The upcoming Firefox 3.6.2 version is not affected as well – the downside is that for now you can only get a release candidate build of Firefox 3.6.2 – click here.
Tags: Mozilla, Firefox, Firefox 3.6, Security, Intevydis
I Hope you LIKE this blog post! Thank you!
What do YOU have to say about this
blog comments powered by Disqus
Popular News
By George Norman on 10 Feb 2012
With the release of Wolfram|Alpha Pro, the team behind the popular computational knowledge engine took a very big step forwardBy George Norman on 10 Feb 2012
Microsoft has just announced that this February, as part of the Patch Tuesday program, it will roll out a grand total of 9 security bulletins to all customers all over the world.Related News
By George Norman on 28 Sep 2011
Great news for fans of properly good web browsers: the latest version of the Firefox browser to be released to the public is v 7.0By George Norman on 02 Feb 2012
Version 10.0 of the very popular Firefox web browser has been released to the web. This new version comes with aBy George Norman on 27 Jan 2012
We all start the year with resolutions, such as “this year I’m going to more carefully watch what I eat”, or “this year I will try to be less stressed”. Most times we discard these resolutions just as easily as By George Norman on 08 Nov 2011
The Mozilla Foundation, the non-profit organization behind the Firefox web browser, set Nobember 8th as the release date for the final version of Firefox 8. This means that every user out there will be able to get version 8.0Advertising
Hot Software Updates
Top Downloads
2.
Opera5.
Trillian8.
AIM9.
Skype10.
Ad-Aware12.
Nero13.
Google Earth14.
Picasa15.
Winamp16.
iTunes17.
RealPlayer18.
uTorrent19.
eMule20.
WinRAR21.
BitComet22.
WinZip23.
Shareaza24.
CCleaner25.
Recuva26.
Tweak UI27.
CuteFTP Home29.
Adobe Reader30.
NewsPiperBecome A Fan!
Link To Us!
Update on Critical Firefox 3.6 Vulnerability Uncovered by Russian Researcher
HTML Linking Code
HTML Linking Code





