FYI...
Firefox v11.0 releasedFrom an admin. account, start Firefox, then >Help >About >Check for Updates-or-
Download:
https://www.mozilla.com/firefox/all.htmlMarch 13, 2012
What's new...
-
https://www.mozilla.org/firefox/11.0/releasenotes/Release Notes/Bug fixes ... See:
Known Issues...
Complete list of changes in this release:
-
https://www.mozilla.org/firefox/11.0/releasenotes/buglist.htmlSecurity Advisories:
-
https://www.mozilla.org/security/known-vulnerabilities/firefox.html#firefox11Fixed in Firefox 11
MFSA 2012-19 Miscellaneous memory safety hazards (rv:11.0/ rv:10.0.3 / rv:1.9.2.28)
MFSA 2012-18 window.fullScreen writeable by untrusted content
MFSA 2012-17 Crash when accessing keyframe cssText after dynamic modification
MFSA 2012-16 Escalation of privilege with Javascript: URL as home page
MFSA 2012-15 XSS with multiple Content Security Policy headers
MFSA 2012-14 SVG issues found with Address Sanitizer
MFSA 2012-13 XSS with Drag and Drop and Javascript: URL
MFSA 2012-12 Use-after-free in shlwapi.dll
-
https://secunia.com/advisories/48402/Release Date: 2012-03-14
Criticality level:
Highly criticalImpact: Security Bypass, Cross Site Scripting, Exposure of sensitive information, System access
Where: From remote
CVE Reference(s): CVE-2012-0451, CVE-2012-0454, CVE-2012-0455, CVE-2012-0456 CVSS, CVE-2012-0457, CVE-2012-0458, CVE-2012-0459, CVE-2012-0460, CVE-2012-0461, CVE-2012-0462, CVE-2012-0463, CVE-2012-0464
Solution: Update or upgrade to Firefox versions 11.0 or 10.0.3, Thunderbird versions 11.0 or 10.0.3, and SeaMonkey version 2.8.
-
http://www.securitytracker.com/id/1026801Date: Mar 14 2012
CVE Reference: CVE-2012-0451, CVE-2012-0454, CVE-2012-0455, CVE-2012-0456, CVE-2012-0457, CVE-2012-0458, CVE-2012-0459, CVE-2012-0460, CVE-2012-0461, CVE-2012-0462, CVE-2012-0463, CVE-2012-0464
Impact: Disclosure of authentication information, Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via network
Version(s):
prior to 11
Solution: The vendor has issued a fix (3.6.28, ESR 10.0.3, 11.0)...
___
Firefox v3.6.28 released
March 13, 2012
From an admin. account, start Firefox, then >Help >Check for Updates
-or-
Download:
https://www.mozilla.com/firefox/all-older.html-
https://www.mozilla.org/security/known-vulnerabilities/firefox36.html#firefox3.6.28Fixed in Firefox 3.6.28
-
https://secunia.com/advisories/48414/Release Date: 2012-03-14
Criticality level:
Highly criticalImpact: Cross Site Scripting, System access
Where: From remote
CVE Reference(s): CVE-2012-0455, CVE-2012-0456, CVE-2012-0457, CVE-2012-0458, CVE-2012-0461, CVE-2012-0464
Original Advisory:
http://www.mozilla.org/security/announce/2012/mfsa2012-13.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-14.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-16.htmlhttp://www.mozilla.org/security/announce/2012/mfsa2012-19.htmlSolution: Update to Firefox version 3.6.28 and Thunderbird version 3.1.20.
