Mozilla to skip CSRF bug patch in next Firefox update
Mozilla today said that it will ship security updates to Firefox 3.5 and Firefox 3.6 next Tuesday, ending a debate about whether to wait for a patch that affects Adobe's software. Firefox 3.5.17 and Firefox 3.6.14 will now appear Tuesday, March 1, Mozilla disclosed in meeting notes published today.
Originally slated for release on Feb. 14, the security updates were held while Mozilla developers investigated a bug that affected some, though not all, users of the betas. According to Mozilla, the bug caused some copies of the updates to repeatedly crash. Mozilla then backed out a recent bug fix to retest the betas.
Around the same time, a cross-site request forgery (CSRF) vulnerability surfaced. "Adobe is worried about it being a 0-day and wants us to ship quickly," said Mozilla on its site. The vulnerability is presumably in Firefox, but Mozilla has provided no information on how it may impact Adobe software.