|
|
|
You are here: News > News > Firefox 3.6.3 vulnerability patched up
| » IT Security NEWS |
| » 03 April 2010 |
| Firefox 3.6.3 vulnerability patched up |
It was discovered that Mozilla’s most up-to-date browser contains a serious vulnerability. And, as of the latest, the popular manufacturer of the free and open source browser broadcasted that the update for the glitch in Firefox 3.6.3 will be distributed to its users.
Competition helps in revealing faults
During the Pwn2Own of the year 2010, there was a serious defect found in the security of the latest version of the Mozilla browser, Firefox 3.6.3. And, just recently, the company revealed that a fix was already created in order to deal with this problem. This is actually the patch, which comes a week after when the Firefox 3.6.2 was released. The earlier version of the web browser, however, attends to another kind of serious security fault.
Insertion of malicious codes may be possible
It was Nils of the MWR Infosecurity who found the memory corruption flaw of the Firefox browser at the Pwn2Own event of 2010. The memory corruption flaw begins with the transferring of certain DOM nodes between documents and triggering garbage collection with a perfect timing. And then, there will be an improperly retained node left and there is a possibility that this will be utilized at a specific period of time with the purpose of accomplishing evil tasks. The retained node may then be used in order to activate a malicious code inserted into a computer system.
Updating is the only way to ensure full protection
According to Mozilla Corporation, the said abuse of flaw may only be accomplished in the newest version of Firefox browser, which is the Firefox 3.6. However, the company is also preparing for a fix patch designed only for Firefox 3.5, the earlier edition of the browser. This will serve as a backup plan in case exploiters find a new method of setting off this recently discovered flaw.
Browser remains the same aside from the minute alterations
Firefox 3.6.3 will remain as is but few adjustments on the security of the browser will be nothing but evident. It is very much advised if the online users update their Firefox 3.6 once the new patch is released. The users have two options with regards to how they will update their current browser. An individual can wait for the automated update notification from Mozilla. Another means to acquire this update is to click the Help Menu of the browser and choose the one, which says “Check for updates”.
Feel free to explore the SecPoint website for additional information: SecPoint Press, SecPoint Products, and SecPoint Forum. |