12.21.06
Firefox released a new version 2.0.0.1
Mozilla has released the first update for the Firefox 2.0 browser to fix eight security vulnerabilities.
- XSS using outer window’s Function object
- RSS Feed-preview referrer leak
- Mozilla SVG Processing Remote Code Execution
- XSS by setting img.src to javascript: URI
- LiveConnect crash finalizing JS objects
- Privilege escalation using watch point
- CSS cursor image buffer overflow (Windows only)
- Crashes with evidence of memory corruption (rv:1.8.0.9/1.8.1.1)
Five of the vulnerabilities were listed as “critical” by Mozilla, with two described as “high” priority.Mozilla fixes the bugs faster them other browser.
Mozilla is expected to start pushing Firefox 2.0.0.1 through its update servers and also make the download available from the main Firefox website.
Version 2.0.0.1 allows Firefox to function with Vista with a few loopholes, provided that Firefox cannot be used as the default browser.
Viewed 5183 times by 2837 viewers

















