LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: Corrine on December 15, 2015, 08:34:29 PM

Title: Firefox 43.0 Released with Critical Security Updates
Post by: Corrine on December 15, 2015, 08:34:29 PM
Mozilla sent Firefox Version 43.0 to the release channel.  The update includes four (4) critical, seven (7) high, three (3) moderate and two (2) low security updates.

Version 38.5.0 was released for Firefox ESR.

Mozilla Firefox Release Notes (https://www.mozilla.org/en-US/firefox/43.0/releasenotes/)
Security Updates (https://www.mozilla.org/security/known-vulnerabilities/firefox.html)
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: plodr on December 16, 2015, 04:09:23 PM
Thanks for the ESR notice.
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: satrow on December 16, 2015, 04:22:07 PM
Quote from: plodr on December 16, 2015, 04:09:23 PM
Thanks for the ESR notice.

Likewise  8)
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: winchester73 on December 16, 2015, 04:25:37 PM
Unverified extensions are now disabled automatically ...

How to override for those who are interested:  https://support.mozilla.org/en-US/kb/add-on-signing-in-firefox?as=u&utm_source=inproduct
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: Pete! on December 16, 2015, 08:36:23 PM
If you go to the download page https://www.mozilla.org/en-US/firefox/all/
You'll see that there's finally a 64 bit version available.

Aside from "trial and error":
Does anyone know if there's any way to find out which add-ons and plug-ins (if any) are compatible with the 64 bit version?
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: Corrine on December 19, 2015, 02:55:46 PM
Firefox version 43.0.1 was released with one change:  "Prepare to use SHA-256 signing certificate for Windows builds, to meet new Microsoft signing requirement (1079858)".

There was no update to Firefox ESR.
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: winchester73 on December 22, 2015, 11:11:06 PM
Firefox v43.0.2 was released today, no release notes available yet.
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: Corrine on December 22, 2015, 11:34:44 PM
The "build notes" are here:  https://wiki.mozilla.org/Releases/Firefox_43.0.2/BuildNotes

ESR is also updated.  The latest is version 38.5.1 38.5.2.
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: plodr on December 23, 2015, 12:18:50 AM
Thanks. I just updated Sumatra so now I'll do FF ESR.
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: ky331 on December 23, 2015, 02:34:13 AM
https://www.mozilla.org/en-US/firefox/43.0.2/releasenotes/

Changed - Use a SHA-256 signing certificate for Windows builds, to meet new signing requirements

=============

Remark:   43.0.1 was released to PREPARE to use this signing certificate.   43.0.2 apparently implements such use.
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: ky331 on December 28, 2015, 09:12:36 PM
Firefox 43.0.3 ( https://www.mozilla.org/en-US/firefox/43.0.3/releasenotes/ )


Fixed

â—¦Fix network issue when using Nvidia's Network Access Manager (1233237)

â—¦On some Windows configurations, improve the decoding of some videos on YouTube (1233970)

Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: Corrine on December 28, 2015, 09:40:49 PM
ESR remains at version 38.5.2.
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: ky331 on January 06, 2016, 11:39:53 PM
Firefox 43.0.4 (1/6/2016)

https://www.mozilla.org/en-US/firefox/43.0.4/releasenotes/

Fixed

    Fix for startup crash for users of a third party antivirus tool (Bug 1235537)

    Multi-user GNU/Linux download folders can be created (Bug 1233434)

Changed

    Re-enable SHA-1 certificates (Bug 1236975)

==================================

Available via the internal updater:  Help/About Firefox
Title: Re: Firefox 43.0 Released with Critical Security Updates
Post by: Corrine on January 07, 2016, 03:04:54 AM
Firefox ESR remains at 38.5.2.