Firefox 3.0.8 Fixes Two Critical Security Issues Found in Firefox 3.0.7

firefox-logo1Mozilla had just released its latest Firefox 3.0.8 fixing two critical security holes found in their previous Firefox 3.0.7

Security Issue #1
Arbitrary code execution via XUL tree element

Description: Security researcher discovered that the XUL tree method _moveToEdgeShift was in some cases triggering garbage collection routines on objects which were still in use. In such cases, the browser would crash when attempting to access a previously destroyed object and this crash could be used by an attacker to run arbitrary code on a victim’s computer.

Security Issue #2
XSL Transformation vulnerability

Description: Security researcher discovered that an XSL stylesheet could be used to crash the browser during a XSL transformation. An attacker could potentially use this crash to run arbitrary code on a victim’s computer.

Users who are currently browsing with the Mozilla’s Firefox 3.0.7 are strongly advised to upgrade to the latest Firefox 3.0.8 by following the link here.

Update: Firefox 3.1 Alpha 2



Leave a Reply

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Subscribe to comments feature has been disabled. To receive notification of latest comments posted, subscribe to Tip and Trick Comments RSS feed or register to receive new comments in daily email digest.
Custom Search

Incoming Search Terms for the Article

firefox 3.0.8 crash - firefox 3.0.8 crashes - firefox 3.08 crashes - firefox 3.0.8 problems - firefox 3.08 - Firefox issues - firefox - firefox 3.0.8 crashing - firefox 3.08 crash - mozilla 3.08 - firefox 3.08 tweaks - Firefox 3.0.8 hangs - 3.08 firefox - firefox 3.08 crashing - firefox 3.08 hangs - firefox 3.0.8 gmail problems - gmail not working with firefox 3.0.8 - firefox start download fre 3.0.8 portques - firefox francais - firefox 3.0.8 tweak - tweaking firefox 3.0.8 - firefox 3.0.8 gmail problem - firefox 3.0.8 vista problems - tweak firefox 3.0.8 - firefox 3.08 problems - w - firefox 3.0.8 gmail - Firefox français - firefox 3.0.8 hang - m - firefox 3.0.8 tweaks - firefox 3.0.8 crash on startup - firefox 3.0.8 issues - i was attempting to download kaspersky and firefox closed - firefox 3.0.7 xsl transformation - Firefox 3.0.8 - cache:TgWRebuDGZwJ:www.mydigitallife.info/2009/03/07/download-new-mozilla-firefox-version-307/lt/ mozilla parsisiusti - mozilla 3.08 crashing - security - firefox 3.0.7 cannot connect to internet - Firefox 3.0.7 francais - firefox 3.08 crashes in vista - Two security holes in Firefox 3.0.8 - firefox 3.0.8 cannot connect to internet - mozilla firefox 3.0.8 nederlands - tweak firefox 3.08 - Firefox 3.0.8 craches - firefox 3.08 password problem - mozilla firefox 3.08 greek - firefox 3.0.8 crash gmail -