Friday, December 22, 2006

Vulnerabilities Fixed -Firefox 2.0.0.1


Mozilla fixed the following 8 known vulnerabilities in Firefox 2 with its release of Firefox 2.0.0.1.

MFSA 2006-76 XSS using outer window's Function object
MFSA 2006-75 RSS Feed-preview referrer leak
MFSA 2006-73 Mozilla SVG Processing Remote Code Execution
MFSA 2006-72 XSS by setting img.src to javascript: URI
MFSA 2006-71 LiveConnect crash finalizing JS objects
MFSA 2006-70 Privilege escallation using watch point
MFSA 2006-69 CSS cursor image buffer overflow (Windows only)
MFSA 2006-68 Crashes with evidence of memory corruption (rv:1.8.0.9/1.8.1.1)

If you have Firefox 2 then you must have been prompted for automatic updates which would have fixed the above vulnerabilities.

You can get Firefox 2.0.0.1 here.

No comments: