New Firefox patches authentication security holes

Two critical problems with how Mozilla's browser handles authentication processes could let an attacker see encrypted data or take over a machine.

Mozilla on Monday released two new versions of Firefox, 3.5.2 and 3.0.13, to patch two critical security holes. You can download the Windows and Mac versions of 3.5.2 from CNET Download.com, or go to Mozilla for the Linux build and Firefox 3.0.13.

"We strongly recommend that all Firefox users upgrade to this latest release," Mozilla said in a blog posting about the security issue.

The first vulnerability could let an attacker run arbitrary code on a person's computer by sending specially crafted authentication information called certificate.

The second vulnerability, disclosed last week, involves a flaw in certificate authentication technology that could potentially let an attacker gain access to encrypted information or issue a bogus update to Firefox.

Featured Video
6
This content is rated TV-MA, and is for viewers 18 years or older. Are you of age?
Sorry, you are not old enough to view this content.

The problem with hoarding photos on your phone

Do you have hundreds (or thousands) of photos on your phone? This one's for you.

by Sharon Profis