Firefox 3.6.2 Plugs Critical Security Hole | eWeek

Firefox 3.6.2 Plugs Critical Security Hole

Written By
Brian Prince
Brian Prince
Mar 23, 2010
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Mozilla has swatted a critical bug in its Firefox browser ahead of schedule.

The flaw, which was discovered by Intevydis founder Evgeny Legerov, had caused enough of a stir to prompt Germany’s B??rgerCERT to advise users to ditch the browser until it was fixed.

According to Mozilla, the Web Open Font Format (WOFF) decoder contains an integer overflow in a font decompression routine. As a result, too small a memory buffer could be allocated to store a downloaded font, and an attacker could exploit the situation to crash a victim’s browser and execute arbitrary code on the system.

Only Firefox 3.6 was affected by the vulnerability.

“We urge users to promptly update to this release by selecting “Check for Updates…” from the “Help” menu, or by visiting https://www.mozilla.com/ for a free download,” according to Mozilla.

The fix is contained within Firefox 3.6.2, which was initially scheduled to be released March 30. After the German advisory however, Mozilla announced it was moving up the release date. While security researchers are divided on the idea of switching browsers every time a vulnerability appears, it was not the first time a government had made the recommendation. Germany and France also advised users to ditch Internet Explorer until the vulnerability tied to the Aurora attack on Google was patched. That vulnerability was fixed in January.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.