Mozilla Foundation Security Advisory 2009-34 Announced: July 21, 2009 Reporter: Mozilla developers and community Impact: Critical Products: Firefox Fixed in: Firefox 3.0.12, Firefox 3.5 Description: Mozilla developers and community members identified and fixed several stability bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these crashes showed evidence of memory corruption under certain circumstances and we presume that with enough effort at least some of these could be exploited to run arbitrary code. Workaround: Disable JavaScript until a version containing these fixes can be installed. References: Browser engine crashes - Firefox 3, Firefox 3.5 (CVE-2009-2462) Base64 decoding crash (CVE-2009-2463) Crash with multiple RDFs in XUL tree (CVE-2009-2464) Double frame construction crashes (CVE-2009-2465) JavaScript engine crashes - Firefox 3, Firefox 3.5 (CVE-2009-2466)