Firefox and Thunderbird updates patch security holes
The Mozilla Project has published updates for Firefox, its open source web browser, and the Thunderbird email client to fix several bugs and other critical issues found in previous versions. The latest Firefox 5 rapid release update addresses a total of 8 security vulnerabilities, 5 of which are rated as "Critical" by Mozilla.
Previous versions of the browser (up to and including 4.0.1) contained a bug in a JavaScript Array object that could potentially result in an integer overflow and the execution of malicious code, as well as a crash on multipart/x-mixed-replace images due to memory corruption. A number of critical memory safety hazards in the browser engine have been fixed. Mozilla says that "with enough effort at least some of these could be exploited to run arbitrary code". Other issues include use-after-free errors when viewing an XUL document with script and multiple WebGL crashes. Two moderate holes that could lead to cross-site scripting (XSS) attacks or a violation of the same-origin policy have also been corrected.