Mozilla Firefox 3.5.3 patches a trio of critical vulns | Internet News

Mozilla Firefox 3.5.3 patches a trio of critical vulns

Sep 10, 2009
1 minute read

sr-firefox3.jpg

From the

Time To Update

files:

Mozilla is updating its Firefox web browser to plug holes in its own software and to help prevent users from running other vendors vulnerable software as well.

Firefox 3.5.3 is being released with three critical bug security advisories from Mozilla. There is, “Crashes with evidence of memory corruption” advisory as has been the case with many Firefox release over the past two years.

“Some of these crashes showed evidence of
memory corruption under certain circumstances and we presume that with
enough effort at least some of these could be exploited to run
arbitrary code,” Mozilla states in its advisory.

There is also an interesting, “TreeColumns dangling pointer vulnerability” that was reported to Mozilla by way of the Tipping Point Zero Day Initiative (ZDI). ZDI pays security researchers for their vulnerabilities and then responsibly discloses them to vendors so they can be fixed.

The tree element flaw deals with a XUL (XML User-interface Language) element that could have been abused to let an attacker potentially run arbitrary code.

The final critical advisory issued by Mozilla is privilege escalation issue in the  BrowserFeedWriter element.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.