Mozilla to skip CSRF bug patch in next Firefox update

23.02.2011
Mozilla today said that it will ship security updates to Firefox 3.5 and Firefox 3.6 next Tuesday, ending a debate about whether to wait for a patch that affects Adobe's software.

Firefox 3.5.17 and Firefox 3.6.14 will now appear Tuesday, March 1, Mozilla disclosed in published today.

Originally slated for release on Feb. 14, the security updates were held while Mozilla developers investigated a bug that affected some, though not all, users of the betas. According to Mozilla, the bug caused some copies of the updates to repeatedly crash. Mozilla then backed out a recent bug fix to retest the betas.

Around the same time, a cross-site request forgery (CSRF) vulnerability surfaced. "Adobe is worried about it being a 0-day and wants us to ship quickly," . The vulnerability is presumably in Firefox, but Mozilla has provided no information on how it may impact Adobe software.

Unlike Google's Chrome, Firefox does not bundle Adobe software. But Adobe's Reader and Flash plug-ins are found in most users' browsers.

Adobe has said it knows nothing about a potential zero-day that would affect its software and/or Firefox.