Mozilla Fixes 17 Vulnerabilities in Firefox 36
A total of 17 security holes have been addressed by Mozilla with the release of Firefox 36. The latest version of the Web browser also includes support for the HTTP/2 protocol.
While the number of fixed vulnerabilities is higher than usual, only four of the flaws have been rated critical.
One of the critical issues is a buffer overflow in the libstagefright library (CVE-2015-0829). The bug, reported by a security researcher who uses the online moniker Pantrombka, is caused by invalid MP4 files during video playback. The issue can lead to a potentially exploitable crash, Mozilla said. Another critical vulnerability that leads to a potentially exploitable crash was discovered and reported by Paul Bandha. The researcher identified a use-after-free bug (CVE-2015-0831) when running specific Web content with IndexedDB to create an index.