Mozilla have released updates to Firefox browser to address a bunch of vulnerabilities of which one categorized as critical, four as high and five as moderate.
Affected products are:
- Mozilla Firefox earlier than 46
- Mozilla Firefox earlier than ESR 45.1
- Mozilla Firefox earlier than ESR 38.8
Links to the security advisories with details about addressed security issues:
MFSA 2016-48 Firefox Health Reports could accept events from untrusted domains
MFSA 2016-47 Write to invalid HashMap entry through JavaScript.watch()
MFSA 2016-46 Elevation of privilege with chrome.tabs.update API in web extensions
MFSA 2016-45 CSP not applied to pages sent with multipart/x-mixed-replace
MFSA 2016-44 Buffer overflow in libstagefright with CENC offsets
MFSA 2016-43 Disclosure of user actions through JavaScript with motion and orientation sensors
MFSA 2016-42 Use-after-free and buffer overflow in Service Workers
MFSA 2016-41 Content provider permission bypass allows malicious application to access data
MFSA 2016-40 Privilege escalation through file deletion by Maintenance Service updater
MFSA 2016-39 Miscellaneous memory safety hazards (rv:46.0 / rv:45.1 / rv:38.8)
Fresh version can be obtained via inbuilt updater or by downloading from the product site:
Firefox
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment