Tuesday, February 04, 2014

Mozilla Firefox Version 27.0 Released


Mozilla sent Firefox Version 27.0 to the release channel.  Although the link in provided in the Release Notes, at the time of this posting, the update for Security Fixes has not been updated.  An update will be provided here when the information is updated.

Update:  The security fixes in Version 27.0 include four (4) critical, four (4) high, four (4) moderate and one (1) low security update.

An important security change in Version 27.0 is the default setting to enable both TLS 1.1 and TLS 1.2 by default.  Additional information is available in Mozillazine at Security.tls.version.

Fixed in Firefox 27

  • MFSA 2014-13 Inconsistent JavaScript handling of access to Window objects
  • MFSA 2014-12 NSS ticket handling issues
  • MFSA 2014-11 Crash when using web workers with asm.js
  • MFSA 2014-10 Firefox default start page UI content invokable by script
  • MFSA 2014-09 Cross-origin information leak through web workers
  • MFSA 2014-08 Use-after-free with imgRequestProxy and image proccessing
  • MFSA 2014-07 XSLT stylesheets treated as styles in Content Security Policy
  • MFSA 2014-06 Profile path leaks to Android system log
  • MFSA 2014-05 Information disclosure with *FromPoint on iframes
  • MFSA 2014-04 Incorrect use of discarded images by RasterImage
  • MFSA 2014-03 UI selection timeout missing on download prompts
  • MFSA 2014-02 Clone protected content with XBL scopes
  • MFSA 2014-01 Miscellaneous memory safety hazards (rv:27.0 / rv:24.3)

What’s New

  • NEW -- You can now run more than one service at a time with Firefox SocialAPI, allowing you to receive notifications, chat and more from multiple integrated services
  • CHANGED -- Enabled TLS 1.1 (RFC 4346) and TLS 1.2 (RFC 5246) by default
  • CHANGED -- Added support for SPDY 3.1 protocol 
  • FIXED -- Get Azure/Skia content rendering working on Linux (see 740200)
  • FIXED -- 27.0: Security fixes can be found here

Known Issues

  • Unresolved -- crash in gfxContext::PushClipsToDT with Direct2D 1.1 (d3d11.dll 6.2 or 6.3) (see 805406)
  • Unresolved -- Moving Firefox to background while playing a flash video in full screen mode and bring it back to view will freeze the app (see 809055)
  • Unresolved -- Text Rendering Issues on Windows 7 with Platform Update KB2670838 (MSIE 10 Prerequisite) or on Windows 8.1 has a workaround (see 812695)


To get the update now, select "Help" from the Firefox menu at the upper left of the browser window, then pick "About Firefox."  Mac users need to select "About Firefox" from the Firefox menu.

If you do not use the English language version, Fully Localized Versions are available for download.


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

No comments: