Mozilla has pushed out an update for a major security whole within the browser, announced March 22, 2010. Researcher Evgeny Legerov of Intevydis reported the issue:
…The WOFF decoder contains an integer overflow in a font decompression routine. This flaw could result in too small a memory buffer being allocated to store a downloadable font. An attacker could use this vulnerability to crash a victim’s browser and execute arbitrary code on his/her system…
If you haven’t upgraded your version yet, you can do so by going to Help > Check for Updates OR Help > Apply Downloaded Update Now.


Your Thoughts