Release date:
Updated on:
Affected Systems:
Mozilla Firefox for Android <28.0.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66393
CVE (CAN) ID: CVE-2014-1515
Mozilla Firefox for Android is a Web browser used on mobile devices.
When file: URL is processed in versions earlier than Mozilla Firefox for Android 28.0.1, local files are copied to the SD card. This vulnerability allows attackers to exploit this vulnerability to obtain sensitive information in the Firefox configuration directory.
<* Source: Roee Hay
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mozilla.org/security/
Https://www.mozilla.org/security/announce/2014/mfsa2014-33.html
Https://bugzilla.mozilla.org/show_bug.cgi? Id = 945429
Firefox details: click here
Firefox: click here
Recommended reading:
Mozilla Firefox 24.0 official version can be downloaded
New Feature in Firefox 24: Disable the tab on the right
Debian squeeze install Firefox 15 Latest Version
Replacement of Firefox in Ubuntu
Use apt-get to install FireFox and ThunderBird In Debian Linux