Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Serious software for the not so serious geek.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. Smart Defrag
2. GS Auto Clicker
3. Macrium Reflect FREE Edition
4. Sergei Strelec's WinPE
5. MusicBee
6. Visual C++ Redistributable Runtimes AIO Repack
7. K-Lite Mega Codec Pack
8. ImgBurn
9. Unlocker
10. Format Factory
More >>

top reads

Star 8 Windows Shortcuts That’ll Make You More Productive and Save You Time

Star Windows 10 Not Dead Yet - You Can Still Get Updates For Free

Star What is a '400 Bad Request - Request Header or Cookie Too Large' Error and How to Fix It

Star How to Fix Windows Install Error 0xC1900101

Star How to Force Enable Windows 10 Extended Security Updates If The Option Is Not Showing

Star Windows 11 25H2 is Out: What’s New and How to Get It Now.

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star Boost Your PC Speed with ReadyBoost: How a Thumb Drive Can Enhance Your System's Performance

Star 5 Hidden Windows Tools You’ve Had All Along But Never Use

Star Use the Windows 10 Media Creation Tool Before Support Ends For Windows 10 in 2025


MajorGeeks.Com » News » October 2012 » Firefox 16 re-released fixing multiple vulnerabilities

Firefox 16 re-released fixing multiple vulnerabilities


Contributed by: Email on 10/12/2012 03:19 PM [ comments Comments ]


The latest version of Firefox, version 16, has returned to Mozilla's servers with the release of Firefox 16.0.1 after the discovery of vulnerabilities caused the organisation to remove the just-released open source web browser from circulation. Mozilla's security blog post described the problem as just that of a malicious web site being able to potentially determine the URLs and parameters used and suggested downgrading to Firefox 15.0.1, despite the numerous critical bugs fixed in Firefox 16.

But on Wednesday, Gareth Heyes, an independent security researcher, posted a proof of concept (PoC) which demonstrated that Firefox 16 was somewhat insecure with its Windows location variables, allowing an attacker to open a window pointing at some part of another site (in the PoC, twitter.com), wait for that site to redirect the window to a "logged in" page (a twitter.com profile page) and then retrieve the new location and any associated data (in the PoC, the user's twitter handle). Accessing the location information should normally be prevented by the browser's "Same Origin" policy.

According to Mozilla's advisory though, a similar but separate critical flaw had been found in Firefox 16, Firefox ESR 10.0.8, SeaMonkey 2.13, Thunderbird 16 and Thunderbird ESR 10.0.8 and earlier, which not only disclosed the location object, but, in Firefox 15 and earlier, had the potential for arbitrary code execution. Firefox 16.0.1 closes both these holes. The presence of the flaw in Firefox 15 does, though, raise questions over the previous advice given by Mozilla to downgrade from 16 to 15.

But these were not the only holes fixed in 16.0.1; another security advisory says developers also identified two of the top crashing bugs in the browser engine and that these bugs showed signs of having corrupted memory. Mozilla concludes that it could be possible to exploit these holes to execute code. One of the bugs only affected FreeType on mobile devices and is therefore fixed in Firefox 16.0.1 for Android, while the other is a WebSockets bug in Firefox 16 only and is not present in Firefox ESR.

Firefox 16.0.1 is now being pushed out to the Firefox browser's auto update system and is also available to download via auto-version-detected download or from the all systems and languages page. Firefox 16.0.1 for Android is available in the Google Play store. Thunderbird 16.0.1 is also available for download. Firefox ESR 10.0.9 and Thunderbird ESR 10.0.9 are currently being quality assured and are expected to be released soon. SeaMonkey 2.13.1 has yet to appear on the project's releases page.






« Video game sales plunge in September · Firefox 16 re-released fixing multiple vulnerabilities · 2 arrested after meth lab found under Super 8 motel bed »




Comments
comments powered by Disqus

MajorGeeks.Com » News » October 2012 » Firefox 16 re-released fixing multiple vulnerabilities

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition