Articles in “Security”

Why an outdated Java Plugin is so serious

Recently, Mozilla responded to an imminent threat to Firefox users who have an outdated Java plugin installed: Vulnerable versions of the plugin were blocked automatically (see blog post). Since then, … Read more

Blocklisting Older Versions of Java

Mozilla recently implemented a block for older versions of Java (Version 6 Update 30 and below as well as Version 7 Update 2 and below) which are vulnerable to a … Read more

Update on Address Sanitizer

In a previous blog post, I outlined how the memory error detection tool Address Sanitizier (ASan) can be used with Firefox to find memory problems with a high degree of … Read more

Mozilla at the University of Warwick

On Tuesday 28th February, Mark Goodwin from Mozilla’s Application Security team will be presenting a guest lecture at the University of Warwick. This session will introduce students to web security … Read more

Mozilla Security Changes

We’ve decided to reorganize our security teams and as part of the change we are going to be using this blog in some new ways. The most notable change is … Read more

Mozilla releases to address CVE-2011-3026

Issue The libpng graphics library, used by Firefox and Thunderbird as well as many other software packages, contains an exploitable integer overflow bug. An attacker could craft malicious images which … Read more

Attack against TLS-protected communications

UPDATE 10.18.11: Today, Oracle is releasing a patch update to Java SE to address this vulnerability.  We recommend that users update their Java plugin to ensure that they have the … Read more