Mozilla patches Firefox but not Thunderbird

Mozilla has patched a single critical security vulnerability in the JavaScript engine of Firefox, but has not yet patched Thunderbird.

Share

Mozilla has patched a single critical security vulnerability in the JavaScript engine of Firefox, but has not yet patched Thunderbird.

According to the associated advisory, Mozilla patched the bug primarily for stability reasons, but said that attackers might leverage crashes in JavaScript's garbage collector.

"We have no demonstration that this particular crash is exploitable but are issuing this advisory because some crashes of this type have been shown to be exploitable in the past," the advisory read.

The open source browser is now on version 2.0.0.14.

JavaScript's garbage collector reclaims memory and returns it to the system; its efficiency is an important factor in the performance of JavaScript specifically and Firefox in general.

The Firefox update can be downloaded from the Mozilla site in versions for Windows, Mac OS X and Linux. Users running Firefox can call up the browser's built in updater, or wait for the automatic update notification, which typically appears within 24 to 48 hours after Mozilla posts a new version.

As with fixes issued in March, the new update was not added to Thunderbird, even though the email client uses Firefox's engine. A month ago, David Ascher, the head of Mozilla Messaging, pleaded lack of resources when he explained why JavaScript bugs in Thunderbird weren't fixed, but said it would be patched in "several weeks."

Thunderbird has not been updated since early February.

Mozilla has again warned Thunderbird users that JavaScript was potentially dangerous because patches had not been applied. "Thunderbird shares the browser engine with Firefox and could be vulnerable if JavaScript were to be enabled in mail," the advisory said.

"This is not the default setting and we strongly discourage users from running JavaScript in mail."

Now read:

Opera patches 'severe' attack flaws

Mozilla launches final Firefox 3.0 beta