Firefox 3.6.3 Fixes Object Scope Confusion
Friday, April 2, 2010 at 08:30AM
drStrangeP0rk in Firefox, Updates, Vulnerability, Zero Day

Mozilla Foundation has released an update to Firefox which addresses a retain and scope issues related to objects. Nils from MWR InfoSecuirty was able to use this during the 2010 Pwn2Own contest to defeat Firefox. A moved node incorrectly retained its old scope, thus an attacker could trigger garbage collection Firefox would still be able to use the freed object. Users should update to this version of Firefox.

Article originally appeared on magmatic.com (http://www.magmatic.com/).
See website for complete article licensing information.