
Mozilla Corp. on Wednesday patched a single critical security vulnerability in the JavaScript engine of Firefox, updating the open-source browser to Version 2.0.0.14.
According to the associated advisory, Mozilla patched the bug primarily for stability reasons, but said that attackers might leverage crashes in JavaScript’s garbage collector. “We have no demonstration that this particular crash is exploitable but are issuing this advisory because some crashes of this type have been shown to be exploitable in the past,” the advisory read.
JavaScript’s garbage collector reclaims memory and returns it to the system; its efficiency is an important factor in the performance of JavaScript specifically and Firefox in general.
Firefox 2.0.0.14 can be downloaded from the Mozilla site in versions for Windows, Mac OS X and Linux. Users running Firefox can call up the browser’s built-in updater or wait for the automatic update notification, which typically appears within 24 to 48 hours after Mozilla posts a new version.
Source: ComputerWorld