SecurityGarden

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, October 9, 2012

Mozilla Firefox 16 Released, Includes Critical Security Updates

Posted on 3:36 PM by Unknown
UPDATE: Firefox 16 was pulled from the update channel. See the Mozilla Security Blog: Security Vulnerability in Firefox 16. Until the problems with version 16 are fixed, the previous version 15.0.1 can be downloaded from this direct link: Firefox 15.

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~


Firefox 16 was sent to the release channel today by Mozilla.  Included in the update are eleven (11) critical and three (3) high security updates.

Based on the extensive list of security updates, it is recommended that the update be applied as soon as possible.

Security Updates Fixed in Firefox 16

  • MFSA 2012-87 Use-after-free in the IME State Manager
  • MFSA 2012-86 Heap memory corruption issues found using Address Sanitizer
  • MFSA 2012-85 Use-after-free, buffer overflow, and out of bounds read issues found using Address Sanitizer
  • MFSA 2012-84 Spoofing and script injection through location.hash
  • MFSA 2012-83 Chrome Object Wrapper (COW) does not disallow acces to privileged functions or properties
  • MFSA 2012-82 top object and location property accessible by plugins
  • MFSA 2012-81 GetProperty function can bypass security checks
  • MFSA 2012-80 Crash with invalid cast when using instanceof operator
  • MFSA 2012-79 DOS and crash with full screen and history navigation
  • MFSA 2012-78 Reader Mode pages have chrome privileges
  • MFSA 2012-77 Some DOMWindowUtils methods bypass security checks
  • MFSA 2012-76 Continued access to initial origin after setting document.domain
  • MFSA 2012-75 select element persistance allows for attacks
  • MFSA 2012-74 Miscellaneous memory safety hazards (rv:16.0/ rv:10.0.8)

What's New

  • NEW -- Firefox on Mac OS X now has preliminary VoiceOver support turned on by default
  • NEW -- Initial web app support (Windows/Mac/Linux
  • NEW -- Acholi and Kazakh localizations added
The Release Notes include additional changes and fixed features in version 16.  As with version 15, there the update includes a long list of Bug Fixes, referenced below.

Update

To get the update now, select "Help" from the Firefox menu at the upper left of the browser window, then pick "About Firefox."  Mac users need to select "About Firefox" from the Firefox menu.

If you do not use the English language version, Fully Localized Versions are available for download.

References

  • Common questions after updating Firefox
  • Security Updates
  • Mozilla Firefox Release Notes
  • Bug Fixes 



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Email ThisBlogThis!Share to XShare to Facebook
Posted in Firefox, Mozilla, Security, Updates, Vulnerabilities | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Security Bulletin Advance Notice for August, 2013
    On Tuesday, August 13, 2013, Microsoft is planning to release eight (8) bulletins.  Three of the bulletins are identified as Critical with f...
  • Critical Out-of-Band Update Released for MS10-046
    Microsoft released Security Bulletin MS10-046 out-of-band to address a vulnerability in Windows. The security update is identified as crit...
  • Hotmail Security to Protect and Recover Your Account
    Time and time again I see reports from Hotmail users who have lost control of their e-mail account.  As explained by Walter Harp, Director o...
  • Long Awaited Outlook.com Calendar Refresh Rollout
    The long-awaited Outlook.com calendar refresh has been released and is in the process of being rolled out. Because the servers are grouped i...
  • Microsoft Security Advisory 2269637 Released
    Microsoft released Security Advisory 2269637 which relates to a remote attack vector to a class of vulnerabilities affecting applications t...
  • Oracle Java Update
    Oracle released the Java SE 7u40 today.  In addition to bug fixes and enhancements, the update includes the following: advanced monitoring ...
  • Adobe Reader Security Updates
    Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.03) and earlier versions for Windows and Macintosh. Adobe identif...
  • Advance Notice: Security Updates for Java SE
    The Sun Security Blog published the following update announcement: "On November 3, 2009, Sun will release the following security update...
  • Adobe Flash Player and Adobe Air Security Updates
    Adobe released updates to both Adobe Flash Player and Adobe AIR to correct a critical vulnerability in both products. From the Adobe Securi...
  • Waledac Botnet Takedown
    The Waledac botnet had the capability of sending 1.5 billion spam e-mails per day. During a three-week period in December, 2009, approximat...

Categories

  • Adobe
  • Advisory
  • Amero
  • AntiVirus
  • Apple
  • Ask
  • AVG
  • Bing
  • Browser
  • Child Safety
  • email
  • ESET
  • Ethics
  • Facebook
  • Firefox
  • Firewall
  • FixIt
  • Fraud
  • General
  • Google
  • Hotmail
  • IE10
  • IE6
  • IE7
  • IE8
  • IE9
  • Java
  • Lavasoft
  • malware
  • Microsoft
  • Microsoft Apps
  • Mozilla
  • MVP
  • NCSAM
  • Office
  • Office 2007
  • Office 2010
  • Opera
  • Outlook.com
  • Phishing
  • Privacy
  • safety
  • Search
  • Security
  • Service Pack
  • SkyDrive
  • Skype
  • Software
  • SP1
  • sp2
  • SP3
  • Spotlight
  • Sumatra
  • tutorial
  • UAC
  • Updates
  • Vulnerabilities
  • Windows
  • Windows 7
  • Windows 8
  • Windows Live
  • Windows Live OneCare
  • Windows Vista
  • Windows XP
  • WinPatrol

Blog Archive

  • ►  2013 (93)
    • ►  October (2)
    • ►  September (8)
    • ►  August (9)
    • ►  July (5)
    • ►  June (8)
    • ►  May (7)
    • ►  April (15)
    • ►  March (9)
    • ►  February (16)
    • ►  January (14)
  • ▼  2012 (98)
    • ►  December (7)
    • ►  November (6)
    • ▼  October (11)
      • Firefox 16.0.2 Released to Fix Critical Security I...
      • WinPatrol PLUS for 99 Cents (Limited Time)
      • Oracle Java Quartely Security and Patch Update
      • Adobe Reader and Acrobat Version XI Released
      • Mozilla Firefox Updated to 16.0.1 Due to Security ...
      • Mozilla Firefox 16 Released, Includes Critical Sec...
      • Microsoft Security Bulletin Release for October 2012
      • Critical Adobe Flash Player Update Released
      • FTC Action Against Fake Tech Support Scams
      • Security Bulletin Advance Report for October 2012
      • 2012 National Cyber Security Awareness Month
    • ►  September (5)
    • ►  August (10)
    • ►  July (8)
    • ►  June (12)
    • ►  May (7)
    • ►  April (12)
    • ►  March (6)
    • ►  February (6)
    • ►  January (8)
  • ►  2011 (130)
    • ►  December (8)
    • ►  November (10)
    • ►  October (7)
    • ►  September (12)
    • ►  August (9)
    • ►  July (6)
    • ►  June (13)
    • ►  May (14)
    • ►  April (13)
    • ►  March (15)
    • ►  February (10)
    • ►  January (13)
  • ►  2010 (146)
    • ►  December (10)
    • ►  November (15)
    • ►  October (19)
    • ►  September (15)
    • ►  August (14)
    • ►  July (8)
    • ►  June (19)
    • ►  May (5)
    • ►  April (11)
    • ►  March (6)
    • ►  February (14)
    • ►  January (10)
  • ►  2009 (33)
    • ►  December (11)
    • ►  November (11)
    • ►  October (11)
Powered by Blogger.

About Me

Unknown
View my complete profile