Wednesday, November 30, 2016

Mozilla Firefox Version 50.0.2 Released to Address Critical Zero-Day Vulnerability


FirefoxMozilla sent Firefox Version 50.0.2 to the release channel today to address a critical zero-day vulnerability in the wild.  Firefox ESR was updated to version 45.5.1.

The next scheduled release is December 13, 2016 (5 week cycle with release for critical fixes as needed).

Critical
Additional information about the vulnerability is available in Vulnerability Note VU#791496, "Mozilla Firefox SVG animation nsSMILTimeContainer use-after-free vulnerability".

Note:  As explained in the Pale Moon forum announcement, although significantly diverted from Mozilla development, the question arose as to whether Pale Moon is also vulnerable.  After evaluation, it was reported that it is extremely unlikely that Pale Moon is vulnerable to this exploit.

Update via Twitter message from PaleMoon:
"Despite this, we'll still be releasing a DiD patched update on Dec 2nd that fixes the crash at the root of this."

Update

To get the update now, select "Help" from the Firefox menu at the upper left of the browser window, then pick "About Firefox."  Mac users need to select "About Firefox" from the Firefox menu. If you do not use the English language version, Fully Localized Versions are available for download.

    References




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...




    Monday, November 28, 2016

    Mozilla Firefox Version 50.0.1 Released with Critical Security Update


    FirefoxMozilla sent Firefox Version 50.0.1 to the release channel today.  The update includes one (1) critical security update affecting Firefox versions 49 and 50.  Firefox ESR is not affected.  Also included in the update is a bugfix.

    The next scheduled release is December 13, 2016 (5 week cycle with release for critical fixes as needed).

    Critical

    Fixed

    • Firefox crashes with 3rd party Chinese IME when using IME text

    Update

    To get the update now, select "Help" from the Firefox menu at the upper left of the browser window, then pick "About Firefox."  Mac users need to select "About Firefox" from the Firefox menu. If you do not use the English language version, Fully Localized Versions are available for download.

      References




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...




      Tuesday, November 22, 2016

      Pale Moon Version 27.0.0 Released


      Pale Moon
      Pale Moon has been updated to Version 27.0.0. This is a major release, eight months in development.

      Update:  Version 27.0.1 was released to fix some of the issues that popped up with the new milestone.

      As explained in the Release Notes, Version 27 is a full upgrade of the back-end platform.  This means that many things work different "under the hood".  As a result, you may run into a number of extension compatibility issues and may wish to run the v27 Compatibility Checking Tool.  Also note the "Removed/support features" in the Release Notes.

      Edit Note:   If you are having problems with the upgrade, see Some known issues when upgrading to Pale Moon 27.


      Details from the Release Notes:

      Security highlights:
      • All relevant security fixes up to and including Firefox 50 have been ported across from Mozilla to continue to provide an as secure as possible browser.
      • Several libraries have been updated to their latest versions to pick up any important vulnerability fixes.
      • There's a new option and control to determine whether to save zone information (marking files as "downloaded from the Internet") on downloaded files (Windows+NTFS). You can find this in Options.
      New and updated features:
      • Support for DirectX 11 and Direct2d 1.1 on Windows. This will bring Pale Moon more in line with the capabilities for current-day operating systems and graphics hardware.
      • Update of the Goanna engine to 3.0 - with many changes to layout and rendering for the modern web.
      • Pale Moon now fully supports HTTP/2.
      • Ruby Annotations are now an integral part of the HTML parser, controllable with CSS.
      • Media Source Extensions have been implemented to solve many video playback issues.
        This can be enabled/disabled and configured in Options. It's recommended at this time to not enable MSE for WebM since there are a few issues with it on services like YouTube (e.g. losing audio when looping/skipping).
      • Support for reading and playing so-called "fragmented" MP4 files has been added, further solving media playback issues.
      • Support for SSL/TLS connections to proxy servers.
      • Support for the WOFF2 font format for downloadable fonts.
      • The JavaScript engine has been updated with support for many landmark ECMAScript6 features (chief among them promises and generators). This will solve many of the web compatibility issues that people have started to run into in the past few months (e.g. webmail interfaces, some sites coming up blank because they are script-generated).
      • The way web content is cached has been changed to be more efficient. If you want to immediately take advantage of this, clear your cache.
      Minimum system Requirements (Windows):
      • Windows Vista/Windows 7/8/10/Server 2008 or later
      • Windows Platform Update (Vista/7) strongly recommended
      • A processor with SSE2 instruction support
      • 256 MB of free RAM (512 MB or more recommended)
      • At least 150 MB of free (uncompressed) disk space
      Pale Moon includes both 32- and 64-bit versions for Windows:

      Update

      To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window.  Select About Pale Moon > Check for Updates.




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...