<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VoIP Tech Chat &#187; firefox</title>
	<atom:link href="http://www.voiptechchat.com/tag/firefox/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.voiptechchat.com</link>
	<description>Patrick and Fred Chat... sometimes about VoIP</description>
	<lastBuildDate>Fri, 30 Dec 2011 01:34:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Firefox Security Vulnerability (Not an April Fool&#8217;s Joke)</title>
		<link>http://www.voiptechchat.com/tech/441/firefox-security-vulnerability-not-an-april-fools-joke/</link>
		<comments>http://www.voiptechchat.com/tech/441/firefox-security-vulnerability-not-an-april-fools-joke/#comments</comments>
		<pubDate>Fri, 02 Apr 2010 13:42:29 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=441</guid>
		<description><![CDATA[On 01 APR 2010, the Mozilla Foundation announced a critical update for it&#8217;s popular Firefox web browser (we say popular, since 80% of you reading this are using it). The update corrects a critical security hole accessible from arbitrary code sent &#8230; <a href="http://www.voiptechchat.com/tech/441/firefox-security-vulnerability-not-an-april-fools-joke/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_409" class="wp-caption alignright" style="width: 211px"><a href="http://www.voiptechchat.com/wp-content/uploads/2010/03/firefox.jpg"><img class="size-full wp-image-409" title="firefox" src="http://www.voiptechchat.com/wp-content/uploads/2010/03/firefox.jpg" alt="" width="201" height="196" /></a><p class="wp-caption-text">Upgrade Me</p></div>
<p>On 01 APR 2010, the Mozilla Foundation announced a critical update for it&#8217;s popular Firefox web browser (we say popular, since 80% of you reading this are using it). The update corrects a critical security hole accessible from arbitrary code sent to the browser.</p>
<blockquote>
<h3>Mozilla Foundation Security Advisory 2010-25</h3>
<p><strong>Title</strong>: Re-use of freed object due to scope confusion<br />
<strong> Impact</strong>: Critical<br />
<strong> Announced</strong>: April 1, 2010<br />
<strong> Reporter</strong>: Nils (MWR InfoSecurity)<br />
<strong> Products</strong>: Firefox<br />
<strong> Title</strong>: Re-use of freed object due to scope confusion</p>
<p><strong>Fixed In</strong>: Firefox 3.6.3</p>
<h4>Description</h4>
<p>A memory corruption flaw leading to code execution was reported by security researcher Nils of MWR InfoSecurity during the 2010 Pwn2Own contest sponsored by TippingPoint&#8217;s Zero Day Initiative. By moving DOM nodes between documents Nils found a case where the moved node incorrectly retained its old scope. If garbage collection could be triggered at the right time then Firefox would later use this freed object.</p>
<p>Note: The contest winning exploit only affects Firefox 3.6 and not earlier versions. We will be patching Firefox 3.5 in an upcoming release just in case there is an alternate way of triggering the bug.</p>
<h4>References</h4>
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=555109" onclick="pageTracker._trackPageview('/outgoing/bugzilla.mozilla.org/show_bug.cgi?id=555109&amp;referer=');">https://bugzilla.mozilla.org/show_bug.cgi?id=555109</a></li>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1121" onclick="pageTracker._trackPageview('/outgoing/cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1121&amp;referer=');">CVE-2010-1121</a></li>
</ul>
</blockquote>
<p>This update follows <a href="http://www.voiptechchat.com/tech/408/got-firefox-upgrade-to-3-6-2/">another critical security hole</a> less than 2 weeks earlier. The product can be downloaded from their website or by using the Check for Updates feature of the software (it&#8217;s a very quick update).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/tech/441/firefox-security-vulnerability-not-an-april-fools-joke/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Got Firefox? Upgrade to 3.6.2.</title>
		<link>http://www.voiptechchat.com/tech/408/got-firefox-upgrade-to-3-6-2/</link>
		<comments>http://www.voiptechchat.com/tech/408/got-firefox-upgrade-to-3-6-2/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 12:16:04 +0000</pubDate>
		<dc:creator>Fred</dc:creator>
				<category><![CDATA[tech]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.voiptechchat.com/?p=408</guid>
		<description><![CDATA[If you&#8217;re running Firefox 3.6, Mozilla strongly recommends you update to version 3.6.2. The new version corrects a critical security hole allowing an attacker to crash your browser and/or run arbitrary code on your machine. The Security Warning advises: Mozilla &#8230; <a href="http://www.voiptechchat.com/tech/408/got-firefox-upgrade-to-3-6-2/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_409" class="wp-caption alignright" style="width: 211px"><a href="http://www.firefox.com" onclick="pageTracker._trackPageview('/outgoing/www.firefox.com?referer=');"><img class="size-full wp-image-409" title="firefox" src="http://www.voiptechchat.com/wp-content/uploads/2010/03/firefox.jpg" alt="" width="201" height="196" /></a><p class="wp-caption-text">Upgrade Me</p></div>
<p>If you&#8217;re running Firefox 3.6, Mozilla strongly recommends you update to version 3.6.2. The new version corrects a critical security hole allowing an attacker to crash your browser and/or run arbitrary code on your machine.</p>
<p>The <a href="http://www.mozilla.org/security/announce/2010/mfsa2010-08.html" onclick="pageTracker._trackPageview('/outgoing/www.mozilla.org/security/announce/2010/mfsa2010-08.html?referer=');">Security Warning</a> advises:</p>
<blockquote>
<h3>Mozilla Foundation Security Advisory 2010-08</h3>
<p><strong>Title</strong>: WOFF heap corruption due to integer overflow<br />
<strong>Impact</strong>: Critical<br />
<strong>Announced</strong>: March 22, 2010<br />
<strong>Reporter</strong>: Evgeny Legerov<br />
<strong>Products</strong>: Firefox 3.6 <span id="more-408"></span></p>
<p><strong>Fixed in</strong>: Firefox 3.6.2</p>
<h3>DESCRIPTION</h3>
<p>Security researcher Evgeny Legerov of Intevydis reported that the WOFF decoder contains an integer overflow in a font decompression routine. This flaw could result in too small a memory buffer being allocated to store a downloadable font. An attacker could use this vulnerability to crash a victim&#8217;s browser and execute arbitrary code on his/her system.</p>
<p><em>Note: Support for the WOFF downloadable font format is new in Firefox 3.6 (Gecko 1.9.2); this vulnerability does not affect products built on earlier versions of the Mozilla browser engine.</em></p>
<h3>REFERENCES</h3>
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=552216" onclick="pageTracker._trackPageview('/outgoing/bugzilla.mozilla.org/show_bug.cgi?id=552216&amp;referer=');">https://bugzilla.mozilla.org/show_bug.cgi?id=552216</a></li>
<li><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1028" onclick="pageTracker._trackPageview('/outgoing/web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1028&amp;referer=');">CVE-2010-1028</a></li>
</ul>
</blockquote>
<p>Firefox recommends that all users upgrade to version 3.6.2 to correct this issue. The product can be downloaded from their <a href="http://www.firefox.com/" onclick="pageTracker._trackPageview('/outgoing/www.firefox.com/?referer=');">website</a> or by using the Check for Updates feature of the software.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.voiptechchat.com/tech/408/got-firefox-upgrade-to-3-6-2/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.281 seconds -->

