HomeSecuritySecurity flaw in Firefox 37.0.1

Security flaw in Firefox 37.0.1

Security flaw in Firefox 37.0.1

A security flaw was fixed almost immediately with Firefox 37.0.1.

Firefox 37 was released last week, with Mozilla announcing the release of Firefox version 37.0.1 a few days later, due to a critical security flaw.

In this small Firefox, HTTP/2 Alt-Svc was disabled and the problem that had appeared with frequent "crashes" on systems with third-party software was fixed.

Alt-Svc [Alternative Services] allow a web server to provide an alternative type of access to a site. For example, if a site's server is down, Alt-Svc takes care of redirecting the page to another location.

However, this was only available on websites using the HTTP/1.1 standard and not the new HTTP/2 standard.

The latest version disables HTTP/2 Alt-Svc, so that the browser works smoothly on older sites.

Furthermore, hackers can take advantage of Alt-Svc, and without the user realizing it, redirect the connection to one under their control. Such a problem can lead to breaches if a company is not careful – proof of this is the case of Lenovo with Superfish.

Finally, don't forget to upgrade Firefox to version 37.0.1 by selecting the button with the three horizontal lines in the top right, then the button with the English question mark [?] and finally, select “About Firefox”. The upgrade to the new version will then begin.

 

Source: gr.pcmag.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS