Mozila Firefox 12.0

Choose it to make the web a better place and enjoy your internet life!


Firefox 3.6.12 released

Firefox 3.6.12 fixes a critical security issue that could potentially allow remote code execution:

 

Title: Heap buffer overflow mixing document.write and DOM insertion
Impact: Critical
Announced: October 27, 2010
Reporter: Morten Kråkvik
Products: Firefox, Thunderbird, SeaMonkey

Fixed in: Firefox 3.6.12
  Firefox 3.5.15
  Thunderbird 3.1.6
  Thunderbird 3.0.10
  SeaMonkey 2.0.10

Description

Morten Kråkvik of Telenor SOC reported an exploit targeting particular versions of Firefox 3.6 on Windows XP that Telenor found while investigating an intrusion attempt on a customer network. The underlying vulnerability, however, was present on both the Firefox 3.5 and Firefox 3.6 development branches and affected all supported platforms.

Reading mail in Thunderbird does not pose a risk to users, however the vulnerability is present and could be triggered in RSS feeds if JavaScript is enabled or by an add-on that enables browser-like functionality.

Download the latest Firefox

 

Post comment:

◎welcome to give out your point。

Powered By Z-Blog 1.8 Walle Build 91204

Mozila's.com some Rights Reserved. Latest version:Firefox 11;Firefox older version:Firefox 10,Firefox 9; Firefox 8; Firefox 7 Firefox 6.