Friday, December 10, 2010

Security Fixes From Mozilla

Mozilla has released security bulletins related to found issues in some of their products. Nine of the fixed vulnerabilities are categorized as critical, one as high and one as moderate.

Critical:
MFSA 2010-82 Incomplete fix for CVE-2010-0179
MFSA 2010-81 Integer overflow vulnerability in NewIdArray
MFSA 2010-80 Use-after-free error with nsDOMAttribute MutationObserver
MFSA 2010-79 Java security bypass from LiveConnect loaded via data: URL meta refresh
MFSA 2010-78 Add support for OTS font sanitizer
MFSA 2010-77 Crash and remote code execution using HTML tags inside a XUL tree
MFSA 2010-76 Chrome privilege escalation with window.open and < isindex > element
MFSA 2010-75 Buffer overflow while line breaking after document.write with long string
MFSA 2010-74 Miscellaneous memory safety hazards (rv:1.9.2.13/ 1.9.1.16)

High:
MFSA 2010-83 Location bar SSL spoofing using network error page

Moderate:
MFSA 2010-84 XSS hazard in multiple character encodings


Fresh versions can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Thunderbird
SeaMonkey

No comments: