Firefox 3.5.4 released

A new security, stability and maintenance version of Firefox has been released. With several critical holes plugged it's a recommended download.

As previous releases the most important changes are the security issues that have been plugged: crashes with evidence of memory corruption, upgrade media libraries to fix memory safety bugs, heap buffer overflow in string to number conversion, chrome privilege escalation in XPCVariant::VariantDataToJS(), heap buffer overflow in GIF color map parser and a crash with recursive web-worker calls. Moderate issues that were fixed are: cross-origin data theft through document.getSelection(), crash in proxy auto-configuration regexp parsing and form history vulnerable to stealing. Labeled as low are: download filename spoofing with RTL override, and local downloaded file tampering.

Besides these fixes stability was addressed, the ability to re-submit crash reports was added, and an issue related with Clear Recent History was resolved.

You can update your existing Firefox manually through the Help -> Check for Updates... menu, or you can download the entire binary from Mozilla's site.

Navigation

Chrome

Chrome tracker

Firefox

Firefox tracker

Opera tracker

User login