Firefox 2.0.0.10 was released on Monday, November 26th. The following HIGH (Vulnerability can be used to gather sensitive data from sites in other windows or inject data or code into those sites, requiring no more than normal browsing actions.) impact security issues were fixed in this build:
- MFSA 2007-39 Referer-spoofing via window.location race condition
- MFSA 2007-38 Memory corruption vulnerabilities (rv:1.8.1.10)
- MFSA 2007-37 jar: URI scheme XSS hazard
Users should get automatic notification of the new version within the next 48-hours. Alternatively users can upgrade sooner by either going to the Help Menu and selecting Check For Updates…or downloading Firefox 2.0.0.10 directly via getfirefox.com
Sources:
- Known Vulnerabilities in Mozilla Products (Fx 2.0.0.10)
- Firefox 2 Release Notes (Fx 2.0.0.10)