Mozilla patches 16 security bugs in Firefox 3.6

Largest set of fixes since March includes patches for 9 critical flaws

Mozilla on Tuesday patched 16 vulnerabilities, nine of them critical, in Firefox 3.6, the largest update for the open-source browser since March.

At the same time, the company patched 12 flaws in the older Firefox 3.5.

More than half -- nine out of 16 -- of the vulnerabilities in Firefox 3.6 were rated "critical," Mozilla's highest threat ranking, indicating that hackers may be able to use them to compromise a system running Firefox, then plant other malware on the machine. Of the remainder, two were pegged as "high" risks, while the other five were labeled as "moderate."

Five of the vulnerabilities were reported to Mozilla by HP TippingPoint's Zero Day Initiative (ZDI), one of the two leading commercial bug bounty programs, while two were handed to Mozilla's developers by researchers who work for Google .

Earlier this month, Mozilla had said it was planning to ship Firefox patches before the annual Black Hat security conference , which is slated to start next week in Las Vegas. The company did the same last year, when it refreshed Firefox 3.0 with an 11-patch update just days before 2009's edition of the conference kicked off.

Mozilla currently has plans to produce another Firefox update after Black Hat, presumably to fix any flaws researchers disclose at the popular conference.

Software makers, especially browser developers, occasionally try to preempt potential security conference disclosures with updates. Prior to last March's CanSecWest, a Vancouver, British Columbia conference that features the Pwn2Own hacking contest, Google and Appleupdated their Chrome and Safari browsers to fix several flaws.

Among the flaws fixed yesterday were two in the Firefox 3.6 rendering engine , one that could be exploited by posting malicious PNG images on sites, and two that might trick users into thinking they're at a trusted site when they actually are not.

Mozilla upgraded Firefox less than a week after it boosted bug bounties six-fold, to US$3,000 for each vulnerability rated critical or high.

Unlike Google, which spells out the bounties it pays researchers in its security advisories, Mozilla does not spotlight the vulnerabilities it's bought. According to the criteria it laid out last week, however, Mozilla may have spent as much as $21,000 for seven of the flaws it fixed Tuesday.

Users can update to Firefox 3.6.7 by downloading the new edition or by selecting "Check for Updates" from the Help menu in the browser. Firefox 3.5 users can obtain the patched version 3.5.11 by calling up the integrated update tool.

Join the Good Gear Guide newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags open sourceapplicationsGooglesecuritybrowserssoftwareMalware and Vulnerabilitiesmozilla firefoxmozillaweb browsers

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld (US)
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Armand Abogado

HP OfficeJet 250 Mobile Printer

Wireless printing from my iPhone was also a handy feature, the whole experience was quick and seamless with no setup requirements - accessed through the default iOS printing menu options.

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?