22 March 2010
The Mozilla project has confirmed that a vulnerability is present in its latest version of the popular browser Firefox (version 3.6). The vulnerability is defined as critical and could result in remote code execution.
Only Firefox version 3.6 is vulnerable. Previous versions of Firefox, and Mozilla's other products, like the email client Thunderbyte and the SeaMonkey browser, are not affected.
An updated version of Firefox - version 3.6.2 - is expected to be released by Mozilla 30 March.
More information in Mozilla's security blog postings here:
Mozilla has released version 3.6.2 ahead of the 30 March schedule. Mozilla also released security advisory 2010-08 with more information about the vulnerability.
Norman recommends Firefox users to update their browser to the latest version to be protected from exploits utilizing this vulnerability.