Browsers - Mozilla Closes Security Flaw in Firefox 10 - eWeek Security Watch

Mozilla Closes Security Flaw in Firefox 10

Feb 12, 2012
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Less than two weeks after releasing Firefox version 10, Mozilla has updated its popular Web browser to close a security flaw.

A critical security vulnerability has been fixed in Firefox 10.0.1, Mozilla wrote in its advisory Feb. 10. The serious use-after-free flaw was found in a component that is shared with other Mozilla products, including the Thunderbird mail client and SeaMonkey application suite.

“Mozilla developers Andrew McCreight and Olli Pettay found that ReadPrototypeBindings will leave a XBL binding in a hash table even when the function fails. If this occurs, when the cycle collector reads this hash table and attempts to do a virtual method on this binding a crash will occur. This crash may be potentially exploitable,” Mozilla said in its advisory.

Firefox 9 and earlier versions are not affected by this vulnerability, according to Mozilla.

Mozilla had released Firefox 10 on Jan. 31. Nine security holes had been patched in the new version, of which five had been rated critical. The critical issues addressed included a potential memory corruption flaw, objects being accessible even after being removed, memory safety hazards, malformed stylesheets, and frame scripts bypassing security checks.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.