You are here: silicon.com > Software > Security Strategy

Security Strategy

Mozilla patches "critical" holes in Firefox

Updates for Thunderbird and SeaMonkey too...

Tags: firefox, mozilla, seamonkey, thunderbird

By Joris Evers

Published: 9 November 2006 08:55 GMT

Mozilla has released updates for its Firefox browser, Thunderbird email application and the SeaMonkey application suite to fix "critical" security vulnerabilities.

The vulnerabilities affect 1.5 versions of Firefox and Thunderbird as well as version 1 of the SeaMonkey suite, Mozilla said in its security advisories. The bugs do not affect Firefox 2.0, the latest version of the browser released late last month.

Security monitoring companies Secunia and the French Security Incident Response Team, or FrSirt, deem the issues "highly critical" and "critical", respectively. People who use vulnerable versions of the Mozilla products are urged to upgrade to the fixed versions, both companies said.

Got two seconds?

Make your voice heard - take our latest poll.

Mozilla has fixed a number of bugs that could cause its products to crash or, in some cases, be exploited to hijack a PC, it said in an advisory. Other problems that have been repaired include a flaw that could be abused to run malicious JavaScript and a vulnerability that could let miscreants fake digital signatures, Mozilla said.

Secunia said in its alert: "The security vulnerabilities could be exploited by malicious people to bypass security restrictions, conduct cross-site scripting attacks and potentially compromise a vulnerable system."

Mozilla plans to support Firefox 1.5 until October 2007, one year after it shipped Firefox 2. The security flaws are fixed in Firefox 1.5.0.8, Thunderbird 1.5.0.8 and SeaMonkey 1.0.6. The previous Firefox security update was released in September.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

The Head of Information Security and Privacy Incident Response

The Head of Information Security and Privacy Incident Response is a senior member of the Vulnerability Management team with primary responsibility ...

Esupport Analyst - Contract - Tier 1 Inv Banking

Microsoft Office support experience - Internet browser support experience eg Firefox / IE - Bloomberg experience - Ideally knowledge of supporting ...

CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.





Quick Sitemap Links: