Mozilla Releases Security Updates for Firefox and Firefox ESR

Original release date: August 06, 2015

The Mozilla Foundation has released security updates to address a critical vulnerability in the built-in PDF Viewer for Firefox and Firefox ESR. Exploitation of the vulnerability may allow an attacker to read and steal sensitive local files on the victim’s computer.

Available updates include:

  • Firefox 39.0.3
  • Firefox ESR 38.1.1

US-CERT encourages users and administrators to review the Security Advisory for Firefox and Firefox ESR and apply the necessary updates.


This product is provided subject to this Notification and this Privacy & Use policy.

‘Prohibition Era’ Of Security Research May Be Ahead

LAS VEGAS–Export controls have become a dirty phrase in the security community, especially among researchers, pen testers, and others who rely on vulnerability information and exploits to do their jobs. And if the Wassenaar Arrangement rules proposed by the United States aren’t modified significantly before they’re implemented, dark days may lie ahead for the research […]

Vulnerable MSVC++ runtime distributed with LibreOffice 5.0.0 for Windows

Posted by Stefan Kanthak on Aug 06

Hi @ll,

the just released latest version 5.0.0.5 of LibreOffice.org for Windows
distributes (once again) a completely outdated and vulnerable MSVC++
runtime.

The installer package LibreOffice_5.0.0_Win_x86.msi contains the files

msvcp80.dll 8.0.50727.42
msvcr80.dll 8.0.50727.42
Microsoft.VC80.CRT.manifest 8.0.50727.42

of the initial/RTM release of the MSVC++ Runtime 2005.

These DLLs have been updated serveral times since their…

Security Advisory – "Cross-VM ASL INtrospection (CAIN)"

Posted by antonio on Aug 06

Hi there

We discovered a new attack vector against memory deduplication in
Virtual Machine Monitors (VMM) where attackers can effectively leak
randomized base addresses of libraries and executables in processes
of neighboring Virtual Machines (VM).

The details are described in the security advisory below and in our
WOOT’15 paper:
https://www.usenix.org/conference/woot15/workshop-program/presentation/barresi

Several vendors were notified…