Ramblings of an old Doc

 

Mozilla’s security chief asked Firefox users not to use Firefox 16 until a critical security flaw introduced in ff16 is fixed.

If you use Firefox, it might have updated silently, so please be aware of the problem, termed “Chemspill”:  https://wiki.mozilla.org/Firefox/Planning/2012-10-10

Michael Coates (director of security assistance at Mozilla) said:

“Those who have downloaded Firefox 16 to revert back to Firefox 15.0.1.” The vulnerability could allow a malicious site to potentially determine which websites users have visited and have access to the URL or URL parameters. At this time we have no indication that this vulnerability is currently being exploited in the wild."

Before “reverting”, check your version.

By the way, this includes mobile device versions of Firefox 16.

Source: 

http://www.infopackets.com/news/security/2012/20121012_mozilla_fixes_critical_firefox_flaw.htm

 

*The "fixed" browser is now available. If you haven't configured for auto update and don't have the "fixed" version, go to 

http://www.mozilla.org and download/install it asap.


Comments
on Oct 12, 2012

Sheesh, I just upgraded and then I see this.  My version is 16.0.1 though, is that the fixed version maybe?

 

Edit:  Looks like the fix was put out today, and I just updated today, so I should be fine.

on Oct 12, 2012

Whatever...

on Oct 12, 2012

LightStar
Looks like the fix was put out today, and I just updated today, so I should be fine.

Yep... just fixed. 

on Oct 13, 2012

Updated.

on Oct 14, 2012

I fixed that problem 3 versions ago, using Firefox 19 lol.