Proactive IT Security
 

Critical vulnerability in Mozilla Firefox (UPDATED)

First published: 2010-10-27
Updated: 2010-10-28

A critical vulnerability has been identified in Mozilla Firefox version 3.5 and 3.6.

Critical is Mozilla's highest vulnerability rating.

An exploit that utilized this vulnerability was first observed on the Nobel Peace Prize's web site. See Norman's press release for more information.

More information is also available in Mozilla's Security Blog, which recommends actions that may be performed in order to be protected from this vulnerability.

This security advisory will be updated when more information is available.

Update 2010-10-28

Mozilla has published security updates to Firefox and Thunderbird.

More information about the update for the newest verrsion of Firefox  is available in the release notes for Firefox 3.6.12.

Norman strongly advices affected users to upgrade their Firefox and Thunderbird applications to the latest versions.