﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
6988	firefox-41.0.2	Fernando de Oliveira	ken@…	"[https://ftp.mozilla.org/pub/firefox/releases/41.0.2/source/firefox-41.0.1.source.tar.xz]

[https://ftp.mozilla.org/pub/firefox/releases/41.0.2/MD5SUMS]

d71f0f761c51aeae03e367001afc9f8d

[https://ftp.mozilla.org/pub/firefox/releases/41.0.2/MD5SUMS.asc]

Now 41.0.2, fixes Mozilla Foundation Security Advisory 2015-115

""Security researcher Abdulrahman Alqabandi reported that the fetch() API did not correctly implement the Cross-Origin Resource Sharing (CORS) specification, allowing a malicious page to access private data from other origins. Mozilla developer Ben Kelly independently reported the same issue. CVE-2015-7184""

Following 41.0.1 items NOT changed.
In practice, that CVE is still marked as ""reserved""

[https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/#firefox41.0.1]

== Security Advisories for Firefox ==

Sorted by ''Impact key'' level, not original time stamp order.

{{{
None
}}}

[https://www.mozilla.org/en-US/firefox/41.0.1/releasenotes/]

== Release Notes ==

{{{

Firefox Notes
Version 41.0.1, first offered to Release channel users on September 30, 2015
View notes for:

    Desktop
    Android

What’s New

    New

  • Reference: Release notes for Firefox 41.0

    Fixed

  • Fix a startup crash related to Yandex toolbar and Adblock Plus
    (1209124)
  • Fix potential hangs with Flash plugins (1185639)
  • Fix a regression in the bookmark creation (1206376)
  • Fix a startup crash with some Intel Media Accelerator 3150 graphic
    cards (1207665)
  • Fix a graphic crash, occurring occasionally on Facebook (1178601)
}}}"	enhancement	closed	high	7.9	BOOK	SVN	medium	fixed		
