This article originally appeared in TidBITS on 2010-02-22 at 10:47 a.m.
The permanent URL for this article is: http://db.tidbits.com/article/11028
Include images: Off

Firefox 3.5.8

by Doug McLean

Despite the fact that Firefox 3.6 is available, those who haven't yet upgraded should pay attention to the just-released Firefox 3.5.8 [1], which addresses a handful of critical security vulnerabilities, all of which could lead to memory corruption and the running of arbitrary code. These issues include several JavaScript-related crashing bugs, a vulnerability that existed in the way Firefox's Web Workers handled various data types when processing posted messages, and a problem with how the HTML parser freed used memory. Detailed information [2] regarding the update's security content is available on Mozilla's Web site. (Free, 19 MB)

[1]: http://www.mozilla.com/en-US/firefox/all-older.html
[2]: http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.8