- http://secunia.com/advisories/14938/
"…Release Date: 2005-04-18
Critical: Highly critical
Impact: Security Bypass
Cross Site Scripting
System access
Where: From remote…
Description:
Multiple vulnerabilities have been reported in Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and compromise a user's system… Solution:
Update to version 1.0.3 …"
>>> http://www.mozilla.org/download.html
- http://weblogs.mozillazine.org/asa/archives/007986.html
April 19, 2005
"Over the last few days I've seen several stories around the release of the Firefox 1.0.3 update with ridiculous headlines like "Firefox Comes Under Attack", "Firefox Singed By Security Holes", and "Security Holes Bite Firefox". I understand that sensational sells, and I'm sorry to be the bearer of bad news for all of the lazy journalists out there, but Firefox wasn't hit, or attacked, or bitten, or singed, by anything…So, what should these headlines have read? Well, how about "Firefox Project Attracts More Security Experts" or "Firefox Security Community Grows" :-)
Posted by asa at April 19, 2005 12:32 PM"