﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
6863	firefox-40.0.3	Fernando de Oliveira	Fernando de Oliveira	"[https://ftp.mozilla.org/pub/firefox/releases/40.0.3/source/firefox-40.0.3.source.tar.bz2]

[https://ftp.mozilla.org/pub/firefox/releases/40.0.3/MD5SUMS]

26a64a80cbd5b77d3b0d9734bff5bbad

[https://ftp.mozilla.org/pub/firefox/releases/40.0.3/MD5SUMS.asc]

[https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/#firefox40.0.3]

== Security Advisories for Firefox ==

Sorted by ''Impact key'' level, not original time stamp order.

{{{
Critical

   • Use-after-free when resizing canvas element during restyling ...
     This results in an exploitable crash.

High

   • Add-on notification bypass through data URLs ... This could lead to
     users installing an add-on from a malicious source.
}}}

[https://www.mozilla.org/en-US/firefox/40.0.3/releasenotes/]

== Release Notes ==

{{{
Firefox Notes
Version 40.0.3, first offered to Release channel users on August 27, 2015
View notes for:

    Desktop
    Android

What’s New

    Reference: Release notes for Firefox 40.0.2

   • Changed

     ◦ Disable the asynchronous plugin initialization (1198590)

   • Fixed

     ◦ Fix a segmentation fault in the GStreamer support (GNU/Linux)
       (1145230)

     ◦ Fix a startup crash when using DisplayLink (Windows Only)
       (1195844)

     ◦ Fix a regression with some Japanese fonts used in the <input>
       field (1194055)

     ◦ On some sites, the selection in a select combox box using the
       mouse could be broken (1194733)

     ◦ Some search partner codes were missing (1195683)

     ◦ Various security fixes
}}}"	enhancement	closed	high	7.8	BOOK	SVN	medium	fixed		
