Mozilla Firefox
Firefox 2.0.0.10 addresses problems with fake HTTP Referer headers

Mozilla fixes Firefox flaws

Most users automatically updated

Written by Iain Thomson

Mozilla has released a new version of its Firefox browser containing some bug and security fixes.

Version 2.0.0.10 includes a memory error patch, better handling of digitally signed pages and a workaround to thwart hackers attempting to fake HTTP Referer headers.

"[Security researcher] Gregory Fleischer demonstrated that it was possible to generate a fake HTTP Referer header by exploiting a timing condition when setting the 'window.location' property," said Mozilla in a security advisory.

"This could be used to conduct a Cross-Site Request Forgery attack against websites that rely only on the Referer header as protection against such attacks."

Customers still using Firefox 1.5 are strongly advised to upgrade immediately, while those using version two should get updated automatically.

"If you already have Firefox 2.x, you will receive an automated update notification within 24 to 48 hours. This update can also be applied manually by selecting 'Check for Updates' from the Help menu," said Mozilla.

Mozilla released a beta of Firefox 3.0 on 20 November offering improved phishing protection, new antivirus software and parental control settings.

Tags:

Further reading

Mozilla unveils Firefox 3 beta

For testing purpose only   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Microsoft brings back automatic ActiveX

Eolas settlement allows interactive websites to function without user clicks   More...

Mozilla fixes Firefox flaws and welcomes Leopard

But still some issues running browser on latest Apple Mac OS   More...

Related articles

Four more fixes for Windows Safari

Security updates pile up for Apple browser   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Mozilla patches cross-browser Firefox flaw

Fix does not cover Internet Explorer problem   More...

Apple issues major OS X security update

Safari also patched   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement