Do Firefox for desktop 43.0.2 and 38.5.2 ESR fix any security vulnerability or not?
Steven Ng <[email protected]> Tue, 29 Dec 2015 23:40:13 +0000
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Hi, Can someone please tell me if Firefox for desktop 43.0.2 and 38.5.2 ESR fix any security vulnerability or not? Yesterday, we saw this entry in these 2 webs, but it has been removed this morning (please refer to the attached screenshot.) "2015-150 MD5 signatures accepted within TLS 1.2 ServerKeyExchange in server signature" https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/ https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox-esr/ Also, this web https://www.mozilla.org/en-US/security/advisories/mfsa2015-150/ has been up and down since yesterday, and currently, it is down again. We also noticed that 43.0.3 was released yesterday as well, does 43.0.3 fix any security issue as well? According to https://www.mozilla.org/en-US/firefox/43.0.3/releasenotes/, it only fixes some network issue, please verify. P.S. I also posted my questions here: https://support.mozilla.org/en-US/questions/1101714, any feedback is appreciated. Thanks. Steven Ng Sr. Software Content Analyst HEAT Software (Lumension is now part of the HEAT Software group) P: 480-444-1600 | M: 602-628-3899 | F: 480-970-6323 [email protected]<mailto:[email protected]> | www.heatsoftware.com<http://www.heatsoftware.com/> 8660 East Hartford Drive, Suite 300, Scottsdale, AZ 85255 [RichardsBlackSmaller]