Mozilla patches critical memory bugs

By
Follow google news

Fixes 15 bugs with 10 patches.

Mozilla has patched 15 bugs in its Firefox browser five of which were deemed critical and could be exploited by an attacker to run malicious code and install software requiring no user interaction.

Mozilla patches critical memory bugs

Firefox 25 addresses critical issues including use-after-free vulnerabilities, a memory corruption issue in JavaScript engine, and several memory safety bugs.

Of note, patch MFSA 2013-93 plugged memory safety bugs that could potentially allow an attacker to run code of their choosing, Mozilla warned.

“Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products,” the patch advisory said. “Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code.”

Bugs posing a “moderate” and “high” threat to users were fixed with the remaining five patches in the release. The fixes addressed a number of issues, including a security bypass vulnerability that could lead to information disclosure of local system files and an issue that could be exploited to spoof displayed address bars, leading to clickjacking attacks.

“Clickjacking” is a hacker method used to reroute traffic to websites and online advertisements of the attackers' choosing.

This article originally appeared at scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

CBA builds two AI agents to boost cyber defences

CBA builds two AI agents to boost cyber defences

Researchers uncover 'Darksword' iPhone spyware

Researchers uncover 'Darksword' iPhone spyware

Stryker contains cyber attack on its Microsoft environment

Stryker contains cyber attack on its Microsoft environment

Exploited Google Chrome zero-days added to US must-patch list

Exploited Google Chrome zero-days added to US must-patch list

Log In

  |  Forgot your password?