Firefox

Firefox ShowIP add-on privacy concerns

by certifiedbug on May 1, 2012

in Internet Security

Sophos

A popular Firefox add-on appears to have started leaking private information about every website that users visit to a third-party server, including sensitive data which could identify individuals or reduce their security.

Naked Security reader Rob Sanders alerted us to the activities of the recently updated ShowIP add-on for the Firefox browser.

Currently over 170,000 people are said to be using ShowIP.

What the add-on’s description doesn’t say is that since version 1.3 (released on April 19th 2012) it has also sent – unencrypted – the full URL of sites visited using HTTPS, and sites viewed in Private Browsing mode, to a site called ip2info.org.

The user never realises that the data has been shared with a third-party, unless they use special tools to monitor what data is being sent from their computer.

http://nakedsecurity.sophos.com/2012/05/01/privacy-concern-showip-firefox-add-on/

{ 0 comments }

Firefox 12.0 released

by certifiedbug on April 25, 2012

in Browser

Fixed in Firefox version 12.
MFSA 2012-33 Potential site identity spoofing when loading RSS and Atom feeds
MFSA 2012-32 HTTP Redirections and remote content can be read by javascript errors
MFSA 2012-31 Off-by-one error in OpenType Sanitizer
MFSA 2012-30 Crash with WebGL content using textImage2D
MFSA 2012-29 Potential XSS through ISO-2022-KR/ISO-2022-CN decoding issues
MFSA 2012-28 Ambiguous IPv6 in Origin headers may bypass webserver access restrictions
MFSA 2012-27 Page load short-circuit can lead to XSS
MFSA 2012-26 WebGL.drawElements may read illegal video memory due to FindMaxUshortElement error
MFSA 2012-25 Potential memory corruption during font rendering using cairo-dwrite
MFSA 2012-24 Potential XSS via multibyte content processing errors
MFSA 2012-23 Invalid frees causes heap corruption in gfxImageSurface
MFSA 2012-22 use-after-free in IDBKeyRange
MFSA 2012-21 Multiple security flaws fixed in FreeType v2.4.9
MFSA 2012-20 Miscellaneous memory safety hazards (rv:12.0/ rv:10.0.4)

If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu.

https://www.mozilla.org/firefox/12.0/releasenotes/

Download: https://www.mozilla.org/en-US/firefox/all.html

{ 0 comments }

Firefox and Thunderbird 11.0 released

by certifiedbug on March 16, 2012

in Browser,Software

http://www.mozilla.org/en-US/firefox/11.0/releasenotes/
https://www.mozilla.org/en-US/thunderbird/11.0/releasenotes/

Every six weeks, another Firefox train leaves the station. This week we will release another update, but not on Tuesday as we typically do. There are two reasons for this:

This Tuesday is Microsoft’s scheduled monthly update to Windows, and those updates have interacted badly with our updates before. We don’t have reason to expect specific problems with this month’s updates, but we’d rather take a day or two to understand the impact before we update all of our users.
We’re also waiting for a report from ZDI about a security vulnerability that may affect this new version of Firefox. We expect to receive the report by end of day Monday. Once we can evaluate the vulnerability, we’ll know whether we need to include a fix in Firefox before the update is released.

UPDATE: The security bug reported by ZDI is one we had already identified and fixed through our internal processes. This eliminates the need for us to delay this week’s releases, and we will be shipping them later today. However, in order to understand the impacts of Microsoft’s “Patch Tuesday” fixes, we will initially release Firefox for manual updates only. Once those impacts are understood, we’ll push automatic updates out to all of our users.

If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu.

Download Firefox http://www.mozilla.org/en-US/firefox/all.html
Download Thunderbird https://www.mozilla.org/en-US/thunderbird/all.html

{ 0 comments }

Firefox and Thunderbird 10.0.2 released

by certifiedbug on February 17, 2012

in Browser,Software

Critical: MFSA 2012-11 libpng integer overflow

http://www.mozilla.org/en-US/firefox/10.0.2/releasenotes/
https://www.mozilla.org/en-US/thunderbird/10.0.2/releasenotes/

If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu.

Download Firefox http://www.mozilla.org/en-US/firefox/all.html
Download Thunderbird https://www.mozilla.org/en-US/thunderbird/all.html

{ 0 comments }

Firefox and Thunderbird 10.0.1 released

February 12, 2012

Critical: MFSA 2012-10 :ReadPrototypeBindings Release notes: http://www.mozilla.org/en-US/firefox/10.0.1/releasenotes/ https://www.mozilla.org/en-US/thunderbird/10.0.1/releasenotes/ If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu. Download Firefox http://www.mozilla.org/en-US/firefox/all.html Download Thunderbird https://www.mozilla.org/en-US/thunderbird/all.html

Read the full article →

Firefox and Thunderbird 10.0 released

January 31, 2012

For a complete list of changes see the release notes: http://www.mozilla.org/en-US/firefox/10.0/releasenotes/ https://www.mozilla.org/en-US/thunderbird/10.0/releasenotes/ If you do not receive an update notice when using the application, select “Check for Updates” from the Help menu. Download Firefox 10.0 http://www.mozilla.org/en-US/firefox/all.html Download Thunderbird 10.0 https://www.mozilla.org/en-US/thunderbird/all.html

Read the full article →

Mozilla Firefox 9 staggered rollout

January 17, 2012

Mozilla Wiki We’re still tracking issues for a possible 9.0.2 You can see them @ https://wiki.mozilla.org/Releases/Firefox_9/RRRT Note we are doing a staggered / slow rollout We were manual-update only initially. This is why < 3 million people got 9.0 instead of 9.0.1 We unthrottled automatic updates for the past week (only offering to 10% of [...]

Read the full article →

Firefox 9.0.1 released

December 30, 2011

The latest version of Firefox has the following changes: Added Type Inference, significantly improving JavaScript performance Improved theme integration for Mac OS X Lion Added two finger swipe navigation for Mac OS X Lion Added support for querying Do Not Track status via JavaScript Added support for font-stretch Improved support for text-overflow Improved standards support [...]

Read the full article →

Firefox 8.0 released

November 8, 2011

The latest version of Firefox fixes several stability and security issues. MFSA 2011-52 Code execution via NoWaiverWrapper MFSA 2011-51 Cross-origin image theft on Mac with integrated Intel GPU MFSA 2011-50 Cross-origin data theft using canvas and Windows D2D MFSA 2011-49 Memory corruption while profiling using Firebug MFSA 2011-48 Miscellaneous memory safety hazards (rv:8.0) MFSA 2011-47 [...]

Read the full article →

FireFox Rapid Release-Silent Updates

October 5, 2011

http://blog.lizardwrangler.com/2011/10/03/rapid-release-follow-up/ Update Fatigue. In the past we have been very careful to make sure people know something is changing with their web browser before it changes. We did this to make sure people are aware and in control of what’s happening to their environment. Our position was to err on the side of user notification. [...]

Read the full article →