Mozilla Firefox has been updated to v3.6.3.
This release fixes a critical security issue according to Mozilla Foundation Security Advisory 2010-25:
Title: Re-use of freed object due to scope confusion
Impact: Critical
Announced: April 1, 2010
Reporter: Nils (MWR InfoSecurity)
Products: FirefoxFixed in: Firefox 3.6.3
Description:
A memory corruption flaw leading to code execution was reported by security researcher Nils of MWR InfoSecurity during the 2010 Pwn2Own contest sponsored by TippingPoint’s Zero Day Initiative. By moving DOM nodes between documents Nils found a case where the moved node incorrectly retained its old scope. If garbage collection could be triggered at the right time then Firefox would later use this freed object.
You can update your version through Firefox’s internal updater by opening Firefox and selecting Help > Check for Updates. You can also get the full download here.







