CERT-In wants you to update your Mozilla Firefox browser immediately

CERT-In wants you to update your Mozilla Firefox browser immediately
The Indian Computer Emergency Response Team (CERT-In) is advising users to immediately update their Mozilla Firefox browser as several vulnerabilities have been found. CERT-In has issued an advisory with ‘High’ severity rating as security issues in Firefox browser could allow a remote attacker to steal personal data. Firefox users are advised to update to Mozilla Firefox version 80 and Mozilla Firefox ESR version 68.12 and 78.2

“Multiple vulnerabilities have been reported in Mozilla Firefox which could allow a remote attacker to escalate privileges, bypass security restrictions, access sensitive information, perform spoofing attack, timing-based side channel attack or execute arbitrary code on the targeted system,” said CERT-In.

Describing the vulnerabilities, CERT-In said, these security flaws exist in Mozilla Firefox due to a downgrade attack on the Mozilla Maintenance Service. As per the advisory, other issue include, “improper handling of prompts, improper usage of ECDSA signatures, side channel error in P-384 and P-521, improper resetting of the address bar after the before unload dialog was shown among others.”

A remote attacker could exploit these vulnerabilities by hosting a specially crafted webpage and then convince the user to visit the webpage using the affected product.

Meanwhile, CERT-In recently issued an advisory warning users about a new Android malware strain, called "BlackRock". This malware comes with data stealing capabilities, and is attacking a wide range of Android apps.

The BlackRock malware can ..

Support the originator by clicking the read the rest link below.