techxplore blog
27 Mar

Firefox 2.0.0.13 Ready To Install

I started up Firefox lately and was greeted by the software update.

Firefox 2.0.0.13 Software Update Ready To Install

Yup, that’s the message window that popped up.

Firefox 2.0.0.13 Update Details:

MFSA 2008-19 XUL popup spoofing variant (cross-tab popups)
MFSA 2008-18 Java socket connection to any local port via LiveConnect
MFSA 2008-17 Privacy issue with SSL Client Authentication
MFSA 2008-16 HTTP Referrer spoofing with malformed URLs
MFSA 2008-15 Crashes with evidence of memory corruption (rv:1.8.1.13)
MFSA 2008-14 JavaScript privilege escalation and arbitrary code execution

The most serious security alerts are the following:

MFSA 2008-14 and MFSA 2008-15 are critical vulnerability that can be used to run attacker code and install software, even without user interaction aside from normal browsing.

MFSA 2008-19 and MFSA 2008-18 are high vulnerability that can be used to gather sensitive data from sites in other windows or inject data or code into those sites, even without user interaction aside from normal browsing actions.

You can read more about this security issue from the following site:

Firefox 2.0.0.13 Security Update

For those who have Firefox browser better update it with the latest version before you’ll be hit by sql injection and javascript hacking on your blogs

Leave a Reply