Computer News & Safety – Harry Waldron Rotating Header Image

June 7th, 2012:

Mozilla Firefox version 13 released

Mozilla has recently enhanced security in Firefox to address recently discovered vulnerabilities

Mozilla Firefox version 13 released
http://www.mozilla.org/security/announce/2012/mfsa2012-35.html

QUOTE:  Security researcher James Forshaw of Context Information Security found two issues with the Mozilla updater and the Mozilla updater service introduced in Firefox 12 for Windows. The first issue allows Mozilla’s updater to load a local DLL file in a privileged context. The updater can be called by the Updater Service or independently on systems that do not use the service. The second of these issues allows for the updater service to load an arbitrary local DLL file, which can then be run with the same system privileges used by the service. Both of these issues require local file system access to be exploitable.

References