Mozilla released version 16.0.2 to address a critical security issue which, if unfixed, could be combined with some plugins to perform a cross-site scripting (XSS) attack on users.
Security Update Fixed in Firefox 16.0.2
- MFSA 2012-90 (https://www.mozilla.org/security/announce/2012/mfsa2012-90.html) Fixes for Location object issues
UpdateTo get the update now, select "Help" from the Firefox menu at the upper left of the browser window, then pick "About Firefox." Mac users need to select "About Firefox" from the Firefox menu.
If you do not use the English language version, Fully Localized Versions (http://"https://www.mozilla.org/en-US/firefox/all.html") are available for download.
References
- Common questions after updating Firefox (http://support.mozilla.com/en-US/kb/common-questions-after-updating-firefox)
- Security Updates (https://www.mozilla.org/security/known-vulnerabilities/firefox.html)
- Mozilla Firefox Release Notes (https://www.mozilla.org/en-US/firefox/16.0.2/releasenotes/)
- Version 16 Bug Fixes (http://www.mozilla.org/en-US/firefox/16.0/releasenotes/buglist.html)
Mozilla released what appears to be a minor update to version 17.0.1. I'm not seeing any security updates. From the Release Notes (http://www.mozilla.org/en-US/firefox/17.0.1/releasenotes/):
17.0.1: Font rendering issue in Firefox 17.0 (bug 814101 (http://bugzil.la/814101)) 17.0.1: Reverted user agent change causing some website incompatibilitiesEdit Note: I guess I didn't look far enough down the page. There were a few other fixes in version 17.0.1 as well as two new items. I'm not sure why the additional fixed items were listed at the bottom.
- 17.0.1: Leaving Private Browsing with Social API enabled should reset social components (814554 (http://"https://bugzilla.mozilla.org/show_bug.cgi?id=814554"))
- Pointer lock doesn't work in web apps (769150 (http://"https://bugzilla.mozilla.org/show_bug.cgi?id=769150"))
- Page scrolling on sites with fixed headers (780345 (http://"https://bugzilla.mozilla.org/show_bug.cgi?id=780345"))
New:
- First revision of the Social API (http://"https://blog.mozilla.org/futurereleases/2012/07/06/bringing-social-to-firefox/") and support for Facebook Messenger
- Click-to-play blocklisting implemented to prevent vulnerable plugin versions from running without the user's permission (see blog post (http://"http://blog.mozilla.org/addons/2012/10/11/click-to-play-coming-firefox-17/"))