MA-938.052023: MyCERT Advisory - Mozilla Releases Security Advisories for Multiple Products
1.0 Introduction
Recently, Mozilla has released security advisories to address vulnerabilities in Thunderbird, Firefox and Firefox ESR.
2.0 Impact
A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.
3.0 Affected Products
Mozilla Thunderbird, Firefox and Firefox ESR
4.0 Recommendations
MyCERT encourages users and administrators to review the following advisories and apply the necessary updates:
- Security Vulnerabilities fixed in Firefox 113 Mozilla Foundation Security Advisory 2023-16 - https://www.mozilla.org/en-US/security/advisories/mfsa2023-16/
- Security Vulnerabilities fixed in Firefox ESR 102.11 Mozilla Foundation Security Advisory 2023-17 - https://www.mozilla.org/en-US/security/advisories/mfsa2023-17/
- Security Vulnerabilities fixed in Thunderbird 102.11 Mozilla Foundation Security Advisory 2023-18 - https://www.mozilla.org/en-US/security/advisories/mfsa2023-18/
For updates addressing lower severity vulnerabilities, see the Mozilla Foundation Security Advisories page.
Generally, MyCERT advises the users of this devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
MA-929.042023: MyCERT Advisory - Mozilla Releases Security Advisories for Multiple Products CISA
1.0 Introduction
Recently, Mozilla has released security advisories for vulnerabilities affecting multiple Mozilla products.
2.0 Impact
A cyber threat actor could exploit these vulnerabilities to take control of an affected system.
3.0 Affected Products
- Firefox 112, Firefox for Android 112, Focus for Android 112
- Firefox ESR 102.10
- Thunderbird 102.10
4.0 Recommendations
MyCERT encourages users and administrators to review the following advisories and apply the necessary updates:
- Security Vulnerabilities fixed in Firefox 112, Firefox for Android 112, Focus for Android 112 Mozilla Foundation Security Advisory 2023-13 : https://www.mozilla.org/en-US/security/advisories/mfsa2023-13/
- Security Vulnerabilities fixed in Firefox ESR 102.10 Mozilla Foundation Security Advisory 2023-14 : https://www.mozilla.org/en-US/security/advisories/mfsa2023-14/
- Security Vulnerabilities fixed in Thunderbird 102.10 Mozilla Foundation Security Advisory 2023-15 : https://www.mozilla.org/en-US/security/advisories/mfsa2023-15/
Generally, MyCERT advises the users of this devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
https://www.cisa.gov/news-events/alerts/2023/04/11/mozilla-releases-security-advisories-multiple-products
MA-911.022023: MyCERT Advisory - Mozilla Releases Security Updates for Firefox 110 and Firefox ESR
1.0 Introduction
Recently, Mozilla has released security updates?to address vulnerabilities in Firefox 110 and Firefox ESR.
2.0 Impact
An attacker could exploit these vulnerabilities to take control of an affected system.
3.0 Affected Products
- Mozilla Firefox
- Mozilla Firefox ESR
4.0 Recommendations
MyCERT encourages users and administrators to review Mozilla’s security advisories for Firefox 110 and Firefox ESR 102.8 for more information and apply the necessary updates.
- Firefox 110 - https://www.mozilla.org/en-US/security/advisories/mfsa2023-05/
- Firefox ESR 102.8 - https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/
Generally, MyCERT advises the users of this devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
https://www.cisa.gov/uscert/ncas/current-activity/2023/02/14/mozilla-releases-security-updates-firefox-110-and-firefox-esr
MA-898.122022: MyCERT Advisory - Mozilla Releases Security Updates for Thunderbird and Firefox
1.0 Introduction
Mozilla released security updates to address vulnerabilities in Thunderbird, Firefox ESR, and Firefox.
2.0 Impact
An attacker could exploit these vulnerabilities to take control of an affected system.
3.0 Affected Products
- Mozilla Firefox
- Mozilla Firefox ESR
- Mozilla Thunderbird
4.0 Recommendations
MyCERT encourages users and administrators to review Mozilla’s security advisories for Thunderbird 102.6, Firefox ESR 102.6, and Firefox 108 for more information and apply the necessary updates.
Kindly refer to the following URLs:
- Thunderbird: https://www.mozilla.org/en-US/security/advisories/mfsa2022-53/
- Firefox ESR: https://www.mozilla.org/en-US/security/advisories/mfsa2022-52/
- Firefox: https://www.mozilla.org/en-US/security/advisories/mfsa2022-51/
Generally, MyCERT advises the users of these devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please get in touch with MyCERT via the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
- https://www.cisa.gov/uscert/ncas/current-activity/2022/12/13/mozilla-releases-security-updates-thunderbird-and-firefox
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-53/
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-52/
- https://www.mozilla.org/en-US/security/advisories/mfsa2022-51/
MA-890.112022: MyCERT Advisory - Mozilla Releases Security Updates?for Multiple Products
1.0 Introduction
Recently, Mozilla has released security updates to address vulnerabilities in Thunderbird, Firefox ESR, and Firefox.
2.0 Impact
An attacker could exploit these vulnerabilities to cause user confusion or conduct spoofing attacks.
3.0 Affected Products
- Mozilla Firefox
- Mozilla Firefox ESR
- Mozilla Thunderbird
4.0 Recommendations
MyCERT encourages users and administrators to review Mozilla’s security advisories for Thunderbird 102.5, Firefox ESR 102.5, and Firefox 107 for mitigations and updates.
Kindly refer to the following URLs:
- Mozilla Thunderbird: https://www.mozilla.org/en-US/security/advisories/mfsa2022-49/
- Firefox ESR: https://www.mozilla.org/en-US/security/advisories/mfsa2022-48/
- Firefox: https://www.mozilla.org/en-US/security/advisories/mfsa2022-47/
Generally, MyCERT advises the users of these devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
https://www.cisa.gov/uscert/ncas/current-activity/2022/11/16/mozilla-releases-security-updates-multiple-products
MA-876.102022: MyCERT Advisory - Mozilla Releases Security Updates?for Firefox
1.0 Introduction
Mozilla has released security updates?to address vulnerabilities in Firefox ESR and Firefox.
2.0 Impact
An attacker could exploit these vulnerabilities to cause denial-of-service conditions.
3.0 Affected Products
Firefox ESR 102.4 and Firefox 106
4.0 Recommendations
MyCERT encourages users and administrators to review Mozilla’s security advisories for Firefox ESR 102.4 and Firefox 106 for mitigations and updates.
Generally, MyCERT advises the users of this devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
https://www.cisa.gov/uscert/ncas/current-activity/2022/10/20/mozilla-releases-security-updates-firefox
MA-863.092022: MyCERT Advisory - Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird
1.0 Introduction
Recently, Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird.
2.0 Impact
An attacker could exploit some of these vulnerabilities to take control of an affected system.
3.0 Affected Products
The affected Microsoft products are:
• Mozilla Firefox
• Mozilla Firefox ESR
• Mozilla Thunderbird
4.0 Recommendations
Users and administrators to review the Mozilla security advisories for Firefox 105, Firefox ESR 102.3, and ThunderBird 91.13.1 and apply the necessary updates. Kindly refer to the following URLs:
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-40/
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-41/
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-39/
Generally, MyCERT advises the users of this devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
• https://www.cisa.gov/uscert/ncas/current-activity/2022/09/21/mozilla-releases-security-updates-firefox-esr-thunderbird
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-40/
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-41/
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-39/
MA-853.082022: MyCERT Advisory - Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird
1.0 Introduction
Recently, Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird.
2.0 Impact
An attacker could exploit some of these vulnerabilities to take control of an affected system.
3.0 Affected Product
The affected Mozilla product are Firefox 104, Firefox ESR 91.13, Firefox ESR 102.2 and Thunderbird 91.13, Thunderbird 102.2
4.0 Recommendations
Users and administrators are recommended to review the below URLs and perform the necessary update. Kindly refer to the below URL:
• Fixed in Firefox 104
https://www.mozilla.org/en-US/security/advisories/mfsa2022-33/
• Fixed in Firefox ESR 91.13
https://www.mozilla.org/en-US/security/advisories/mfsa2022-35/
• Fixed in Firefox ESR 102.2
https://www.mozilla.org/en-US/security/advisories/mfsa2022-34/
• Fixed in Thunderbird 91.13
https://www.mozilla.org/en-US/security/advisories/mfsa2022-37/
• Fixed in Thunderbird 102.2
https://www.mozilla.org/en-US/security/advisories/mfsa2022-36/
Generally, MyCERT advises the users of this software to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
• https://www.cisa.gov/uscert/ncas/current-activity/2022/08/23/mozilla-releases-security-updates-firefox-firefox-esr-and
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-33/
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-34/
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-35/
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-36/
• https://www.mozilla.org/en-US/security/advisories/mfsa2022-37/
MA-783.042020: MyCERT Alert - Vulnerabilities in Mozilla Firefox & Firefox ESR
1.0 Introduction
Recently, Mozilla has released Firefox version 74.0.1 and Firefox ESR 68.6.1 to address two (2) critical vulnerabilities. This vulnerability may cause the application to crash and likely to allow the attacker to take control of the affected system. Mozilla has already acknowledged the targeted attacks in the wild abusing this flaw and rated to be critical.
2.0 Impact
The first vulnerability identified in CVE-2020-6819 as a use-after-free bug which caused by race condition when running the nsDocShell destructor. On the other hand, second vulnerability in CVE-2020-6820 also identified as a use-after-free bug which caused by race condition when handling ReadableStream.
3.0 Affected System and Devices
- Firefox < 74.0.1
- Firefox ESR < 68.6.1
4.0 Recommendations
MyCERT highly recommended users of these applications to upgrade to the latest version of the affected products. The current latest versions are as below:
- https://www.mozilla.org/en-US/firefox/74.0.1/releasenotes/
- https://www.mozilla.org/en-US/firefox/68.6.1/releasenotes/
Advisories can be referred at:
Generally, MyCERT advises the users of this devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Fax: +603 - 8008 7000 (Office Hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
SMS: CYBER999 REPORT EMAIL COMPLAINT to 15888
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References
MA-762.012020: MyCERT Advisory - Vulnerabilities in Mozilla Firefox & Firefox ESR
1.0 Introduction
Recently, MyCERT received information from valid resources about exploits in Mozilla Firefox browser. This vulnerability may cause the application to crash and likely to allow attacker to take control of the affected system. Mozilla has already acknowledged the targeted attacks in the wild abusing this flaw and rated to be critical.
2.0 Impact
The vulnerability was identified as a type of confusion bug in IonMonkey JavaSecirpt JIT (Just-inTime) compiler of SpiderMonkey which known as Firefox JavaScript engine. Depending on its privilege, this vulnerability may allow arbitrary execution and will allow attacker to install programs that could view, change, clear data or create new accounts with full user rights.
3.0 Affected Products
- Firefox < 72.0.1
- Firefox ESR < 68.4.1
4.0 Recommendations
MyCERT highly recommended users of these applications to upgrade to the latest version of the affected products. The current latest versions are as below:
Advisories can be referred at:
Generally, MyCERT advises the users of this devices to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.
For further enquiries, please contact MyCERT through the following channels:
E-mail: cyber999[at]cybersecurity.my
Phone: 1-300-88-2999 (monitored during business hours)
Fax: +603 - 8008 7000 (Office Hours)
Mobile: +60 19 2665850 (24x7 call incident reporting)
SMS: CYBER999 REPORT EMAIL COMPLAINT to 15888
Business Hours: Mon - Fri 09:00 -18:00 MYT
Web: https://www.mycert.org.my
Twitter: https://twitter.com/mycert
Facebook: https://www.facebook.com/mycert.org.my
5.0 References