that Mozilla have just made Firefox 3.0.6 - which, of particular note,
serves to resolve a security flaw in the implementation of Javascript
that could potentially allow hackers to inject and run unauthorized code
via an exploit -available for download.
According to Mozilla’s release notes, Firefox 3.0.6 comes with the
following security fixes:
Directives to not cache pages ignore (Low Threat)
XMLHttpRequest allows reading HTTP Only cookies {Low Threat)
Chrome privilege escalation via local .desktop files (Moderate Threat)
Local file stealing with SessionStore (High Threat)
XSS using a chrome XBL method and window.eval (High Threat)
Crashes with evidence of memory corruption (rv:1.9.0.6) (Critical Threat)
You can download Firefox 3.0.6 now via Mozilla.


No comments:
Post a Comment