Does anyone know anything about this? I saw a brief mention of it on ALE (Atlanta Linux Enthusiasts) mail list pointing to; http://blog.mozilla.com/security/200...in-firefox-35/.
To fix a security vulnerability in the previous release, Firefox developers have issued an early follow-up version 3.6.2 for immediate implementation.
Referenced CVEs:
CVE-2009-2654
Description:
===========================================================
Ubuntu Security Notice USN-811-1 August 05, 2009
firefox-3.0, xulrunner-1.9 vulnerability
CVE-2009-2654
===========================================================
Just thought I would share this here considering there was an update today.
http://blog.mozilla.org/security/201...in-firefox-16/
Quote:
Impact:
The vulnerability could allow a malicious site to potentially determine which websites users have visited and have access to the URL or URL parameters.
Thursday marked yet another chapter in the short, rocky history of Mozilla's Firefox 3.5 browser, as the foundation released a security update a little more than two weeks after unveiling it. Firefox 3.5.1 fixes a JavaScript vulnerability in version 3.5 that exposed users to so-called drive-by attacks.
I have plesk 10.3.1 and I received following email from the Plesk admin
Parallels, the manufacturer and distributor of the Plesk Control
Panel, has identified a SQL injection security vulnerability in some
older versions of the control panel.
Mozilla released Firefox 5 earlier this week, just three months after rolling out Firefox 4 and a month after it released version 5 in beta. Version 5 has "more than 1,000 improvements," which include the "Do Not Track" privacy feature and support for the CSS Animations standard, among other things.
The German government has issued a stern warning to telling them not to use Firefox because the browser contains a critical security vulnerability.
On December 13, Canonical published in a security notice details about a unity-firefox-extension vulnerability for its Ubuntu 12.10 (Quantal Quetzal) operating system.
According to Canonical, unity-firefox-extension (Firefox extension for Unity Integration) could have been made to expose sensitive information over the network.
It was discovered that unity-firefox-extension bypassed the same orig