New Firefox patches authentication security holes

Two critical problems with how Mozilla's browser handles authentication processes could let an attacker see encrypted data or take over a machine.

Mozilla on Monday released two new versions of Firefox, 3.5.2 and 3.0.13, to patch two critical security holes. You can download the Windows and Mac versions of 3.5.2 from CNET, or go to Mozilla for the Linux build and Firefox 3.0.13.

"We strongly recommend that all Firefox users upgrade to this latest release," Mozilla said in a blog posting about the security issue.

The first vulnerability could let an attacker run arbitrary code on a person's computer by sending specially crafted authentication information called certificate.

The second vulnerability, disclosed last week, involves a flaw in certificate authentication technology that could potentially let an attacker gain access to encrypted information or issue a bogus update to Firefox.

Featured Video

VTech hack exposes 5 million accounts, including kids' photos, chats

The toymaker stores personal data and photos in a way that may be easy for hackers to access. Also, Amazon shows off its latest design for delivery drones.

by Bridget Carey