Recent Firefox update caused crashes, possible hole
By Ed Oswald, BetaNews
April 17, 2008, 10:57 AM
While there is no evidence of an exploit as of yet, Mozilla is taking a proactive measure to fix the issue before it could be.
A problem with stability which resulted in crashes and evidence of memory corruption was remedied in Firefox 2.0.0.13, however apparently the fix did not completely close any holes.
"We have no demonstration that this particular crash is exploitable but are issuing this advisory because some crashes of this type have been shown to be exploitable in the past," Mozilla said in an advisory.
Thunderbird is also affected, however JavaScript needs to be enabled. By default, this is not, and Mozilla said it discourages users from running scripts within mail.
JavaScript garbage collection problems have cropped up in the past. In February 2006, Mozilla addressed several issues within Firefox 1.5 which also posed a memory corruption and arbitrary code risks.
CLARIFICATION We made an adjustment to our headline for accuracy: The latest fix for Firefox 2, version 2.0.0.14, addresses the problem raised by the Mozilla advisory.


Add a Comment (90 Comments)
BetaNews reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic. Foul language and personal attacks will not be tolerated.