Risk: High
Debian has issued an update for Mozilla Firefox, fixing 13 vulnerabilities.
These flaws exist due to a variety of reasons, including lenient handling of HTTP header syntax, Unicode Byte-order-Mark (BOM) being stripped from UTF-8 pages during the conversion to Unicode before the parser sees the web page and integer overflow.
The vulnerabilities identified could result in an attacker conducting cross site scripting, gaining system access and bypassing security. Debian users are urged to upgrade dependent on the platform being used. Debian GNU/Linux stable (sarge) users should upgrade to version 1.0.4-2sarge6 and Debian GNU/Linux unstable (sid) users should upgrade to version 1.5.dfsg+1.5.0.2-2.