firefox 306 header

Just a very brief heads-up to let you know, if you didn’t already, that Mozilla have just made Firefox 3.0.6 – which, of particular note, serves to resolve a security flaw in the implementation of Javascript that could potentially allow hackers to inject and run unauthorized code via an exploit -available for download.

According to Mozilla’s release notes, Firefox 3.0.6 comes with the following security fixes:

  • Directives to not cache pages ignore (Low Threat)
  • XMLHttpRequest allows reading HTTP Only cookies {Low Threat)
  • Chrome privilege escalation via local .desktop files (Moderate Threat)
  • Local file stealing with SessionStore (High Threat)
  • XSS using a chrome XBL method and window.eval (High Threat)
  • Crashes with evidence of memory corruption (rv:1.9.0.6) (Critical Threat)

You can download Firefox 3.0.6 now via Mozilla.

Looking for more? See Computers | Net Resources or scroll down for carefully selected related items that may also be of interest to you.

Mozilla Firefox 3.0.6 Released [Javascript Exploit & Display Issues Resolved]

Related Reading on TFTS