Mozila Firefox 10.0

Choose it to make the web a better place and enjoy your internet life!


Firefox 3.6.3 released April 1st, 2010.

Firefox 3.6.3 fixes a critical security issue that could potentially allow remote code execution as follow .

Title: Re-use of freed object due to scope confusion
Impact: Critical
Announced: April 1, 2010
Reporter: Nils (MWR InfoSecurity)
Products: Firefox

Fixed in: Firefox 3.6.3

Description

A memory corruption flaw leading to code execution was reported by security researcher Nils of MWR InfoSecurity during the 2010 Pwn2Own contest sponsored by TippingPoint's Zero Day Initiative. By moving DOM nodes between documents Nils found a case where the moved node incorrectly retained its old scope. If garbage collection could be triggered at the right time then Firefox would later use this freed object.

The contest winning exploit only affects Firefox 3.6 and not earlier versions. We will be patching Firefox 3.5 in an upcoming release just in case there is an alternate way of triggering the bug.

Download the latest Firefox here.

Post comment:

◎welcome to give out your point。

Powered By Z-Blog 1.8 Walle Build 91204

Mozila's.com some Rights Reserved. Latest version:Firefox 10;Firefox older version:Firefox 9; Firefox 8; Firefox 7 Firefox 6.