Mozilla Releases security updates

Number: AV16-146
Date: 21 September 2016

Purpose

The purpose of this advisory is to raise awareness of multiple vulnerabilities in Mozilla Firefox and Firefox ESR for which updates are now available.

Assessment

Mozilla released security updates to address 30 vulnerabilities (6 Critical, 19 High, 3 Moderate and 2 Low) in Firefox and Firefox ESR. The severity of these issues ranges from low to critical.

Version affected:
Firefox versions prior to 49.0
ESR versions prior to 45.4

CVE References: CVE-2016-2827, CVE-2016-5250, CVE-2016-5256, CVE-2016-5257, CVE-2016-5261, CVE-2016-5270, CVE-2016-5271, CVE-2016-5272, CVE-2016-5273, CVE-2016-5274, CVE-2016-5275, CVE-2016-5276, CVE-2016-5277, CVE-2016-5278, CVE-2016-5279, CVE-2016-5280, CVE-2016-5281, CVE-2016-5282, CVE-2016-5283, and CVE-2016-5284.

Suggested action

CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.

References

https://www.mozilla.org/en-US/security/advisories/mfsa2016-85/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-86/

Date modified: