Mozilla has published a security advisory to address multiple vulnerabilities found in Firefox. A remote attacker would entice a user running the vulnerable browser to open a web page with specially crafted content to exploit the vulnerabilities.
Successful exploitation of the vulnerabilities could allow a malicious website to query browsing history.
Mozilla has released a new version of the product to address the issues and they can be downloaded at the following URL:
Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
https://www.mozilla.org/en-US/security/advisories/mfsa2017-27/
https://www.hkcert.org/my_url/en/alert/17120501
https://www.us-cert.gov/ncas/current-activity/2017/12/04/Mozilla-Releases-Security-Update-Firefox
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7843
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7844