Mozilla patches Firefox and Firefox ESR vulnerabilities

Mozilla patches Firefox and Firefox ESR vulnerabilities

Recently Mozilla has released the security updates for patching the vulnerabilities found in** Firefox** and Firefox ESR. These vulnerabilities might have made it possible for a remote attacker to take control of an affected system.

On 11th December, the US-CERT advisory stated,“The National Cybersecurity and Communications Integration Center (NCCIC), part of the Cybersecurity and Infrastructure Security Agency (CISA), encourages users and administrators to review the Mozilla Security Advisories for Firefox64 and FirefoxESR 60.4 and apply the necessary updates.” Among the 17 CVEs released for both Firefox and Firefox ESR, three were rated critical where else four of them were rated high.

It is to be noted that all the critical vulnerabilities had memory safety bugs in both Firefox 64 and Firefox ESR 60.4. Other patches included fixes for buffer overflow and out of bounds read in ANGLE library with TextureStorage11, use-after-free with select element bugs, and other buffer overflow flaws