There are multiple
vulnerabilities in Firefox and related products including Thunderbird,
SeaMonkey and the Mozilla Suite. This CERT
Advisory contains additional information.
Posted Apr 27, 2006 15:46 UTC (Thu) by JoeBuck (subscriber, #2330)
[Link]
As the CERT advisory makes clear, all of these issues are fixed upstream in version 1.5.0.2 of Firefox. It would be best to put that information up front in the LWN article, so anyone with a slow-moving distributor knows he/she has the option of going direct to mozilla.com for the upgrade.
Ditto for other apps that upstream ships binaries for or that can be built easily with configure, make, make install: it would be appropriate to let people know when there is a security fix in the upstream source tarball and what version number has the fix.