Thursday, August 27, 2015

Mozilla Firefox Version 40.0.3 Released with Security Updates


Firefox
Mozilla sent Firefox Version 40.0.3 to the release channel.  The update includes one (1) critical and one (1) high security update.

Firefox ESR version has been updated to 38.2.1.


Fixed in Firefox 40.0.3

  • 2015-95 Add-on notification bypass through data URLs
  • 2015-94 Use-after-free when resizing canvas element during restyling 

What’s New

  • Changed -- Disable the asynchronous plugin initialization (1198590)
  • Fixed -- Fix a segmentation fault in the GStreamer support (GNU/Linux) (1145230)
  • Fixed -- Fix a startup crash when using DisplayLink (Windows Only) (1195844)
  • Fixed -- Fix a regression with some Japanese fonts used in the field (1194055)
  • Fixed -- On some sites, the selection in a select combox box using the mouse could be broken (1194733)
  • Fixed -- Some search partner codes were missing (1195683)




Update

To get the update now, select "Help" from the Firefox menu at the upper left of the browser window, then pick "About Firefox."  Mac users need to select "About Firefox" from the Firefox menu. If you do not use the English language version, Fully Localized Versions are available for download.

References

Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...








Wednesday, August 26, 2015

Pale Moon Version 25.7 Released with Security Updates


Pale Moon

Pale Moon has been updated to version 25.7.  This update includes critical security updates as well as some code cleanup and fixes.

Included in the security updates is an update described as "DiD", "Defense-in-Depth.  This fix does not apply to an actively exploitable vulnerability in Pale Moon.  Rather, it is a preventative measure to prevent future vulnerabilities caused by the same code when surrounding code changes.

Security fixes:
  • Added protection against potential bugs where our SVG mPositions is out of sync with the characters in the DOM. DiD
  • Fixed use-after-free vulnerability in XMLHttpRequest::Open() (CVE-2015-4492)
  • Fixed use-after-free vulnerability in the StyleAnimationValue class (CVE-2015-4488)
  • Fixed crash or memory corruption in nsTArray (CVE-2015-4489)
  • Fixed crash or memory corruption in nsTSubstring::ReplacePrep (CVE-2015-4487)
  • Fixed potential escalation of privileges or crash (out-of-bounds write) via a crafted name in MARs (x64 only) (CVE-2015-4482)
  • Fixed an issue that would allow man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request. (CVE-2015-4483)


Fixes/changes:

A complete list of the fixes, changes and additions is available in the Release Notes.

    Minimum system Requirements (Windows):
    • Windows Vista/Windows 7/Windows 8/Server 2008 or later
    • A processor with SSE2 support
    • 256 MB of free RAM (512 MB or more recommended)
    • At least 150 MB of free (uncompressed) disk space
    Pale Moon includes both 32- and 64-bit versions for Windows:
    Other versions:

      Update

      To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window.  Select About Pale Moon > Check for Updates.



      Home
      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...









      Friday, August 21, 2015

      OEM Supported Systems for Windows 10 Upgrade

      Windows 10

      It has been over three weeks since Windows 10 was officially released.  However, there are still inquiries in forums with people asking why they haven't received the upgrade to Windows 10 and are still getting the "Thank you" message:

      Windows 10 Thank you for reserving your free upgrade

      Granted, with an anticipated billion computers to be upgraded, many are still in the queue.  There is also another side of the coin.  Although Microsoft indicated that all qualified Windows 7 and Windows 8.1 computers could upgrade to Windows 10, it seems that for many devices the "qualification" is dependent upon the OEM.  For example, as stated by a Dell representative here,
      "As per the update from Microsoft, all Windows 7 and Windows 8.1 systems should be eligible for the Windows 10 free upgrade. But, Dell will decide which systems Dell will validate and support with Windows 10."
      Other OEMs may be following a similar procedure.  If you are still waiting to get the upgrade, it may be beneficial to check the OEM website.

      The links below may be helpful in determining whether your device has been approved by the OEM as supported for Windows 10 upgrade.

      You may also want to check the OEM website for any driver updates for your device.
           
      h/t:  Thanks, Techie, for helping to track down the references!

      Home
      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...