Jump to content
The Inquirer-Home

Firefox fixes SSL flaws

Get it while its hot
Tuesday, 4 August 2009, 15:40

MOZILLA'S FIREFOX versions 3.5.2 and 3.0.13 are available for download to fix several known security problems.

As per usual the Mozzarella team strongly recommends that all users upgrade to the latest release, and it looks like you'd be a fool not to do so. The new releases patch several security issues and four out of the six for Firefox 3.5 are rated as critical. They should remove the risks of known SSL spoofing hacks and memory corruption problems that can open the browser up to exploits as well as crashes.

Advisory MFSA 2009-42 is described loosely as a "compromise of SSL-protected communication" while the MFSA 2009-45 summary says "crashes with evidence of memory corruption".

Whether those advisories mean anything to you or not, as a general rule critical security vulnerabilities can be exploited either to run attack code or install malicious software, or both, without the user's knowledge.

Firefox 3.0.13 has also been updated and it too has had SSL vulnerabilities patched. Mozilla said that two of its three security problems are rated as critical. It described those as a "heap overflow in certificate regexp parsing" and "compromise of SSL-protected communication", while the third is merely a 'moderate' issue.

Of course if you have better things to do, the automatic update should kick in soon. Just be advised to avoid using SSL in the meantime, which means don't do any online banking or commercial transactions.

With the Firefox project having announced that it surpassed 1 billion downloads of the browser last weekend it should be expecting a lot of upgrade traffic. µ

Share this:

Comments
heh

This is exactly why nobody except for muppets use IE anymore, problems like this go unfixed for months if not years.

posted by : heh, 04 August 2009 Complain about this comment
FireFox rocks

no kidding. my auto dl kicked in and I have learned to patiently await new versions knowing full well that most of the fixes are security related.

Kudos to Firefox for keeping pace with technology and thwarting spoofing and scam. And a round of applause for sites that adopt Extended Validation SSL to provide users safer "sandboxes" to play in.

posted by : Juno P, 07 August 2009 Complain about this comment
Advertisement
Subscribe to the INQ Newsletter
Sign-up for the INQBot weekly newsletter
Click here to sign up Existing user
Advertisement
INQ Poll

Christmas computer sales

Will you be buying a new computer this Christmas?