Home Area 51 Browsers Firefox Mozilla patches 'critical' Firefox security hole

Firefox Logo 2Patch it! Patch it now! 

From Mozilla’s advisory:

Mozilla developers Andrew McCreight and Olli Pettay found that ReadPrototypeBindings will leave a XBL binding in a hash table even when the function fails. If this occurs, when the cycle collector reads this hash table and attempts to do a virtual method on this binding a crash will occur. This crash may be potentially exploitable.

Mozilla rates this a “critical” vulnerability that can be used to run attacker code and install software, requiring no user interaction beyond normal browsing. 

Read the entire article...

blog comments powered by Disqus