Friday, December 16, 2016

Pale Moon Version 27.0.3 Released with Security Updates


Pale Moon
Pale Moon has been updated to Version 27.0.3.  The update addresses a number of bugs and regressions with the new milestone release as well as security updates.  Included in the updates are DiD* patches.
*DiD stands for "Defense-in-Depth" and is a fix that does not apply to an actively exploitable vulnerability in Pale Moon but prevents future vulnerabilities caused by the same code when surrounding code changes, exposing the problem.
Details from the Release Notes:

Security and Crash fixes:
  • Fixed use-after-free while manipulating DOM events and removing audio elements (CVE-2016-9899).
  • Fixed CSP bypass using the marquee tag (CVE-2016-9895).
  • Fixed a vulnerability in the internal Jetpack modules (CVE-2016-9903). DiD
  • Fixed use-after-free in Editor while manipulating DOM subtrees (CVE-2016-9898).
  • Fixed an error in the buffer logic in http-chunked decoder.
  • Fixed a crash in generational GC code (not in use by default) DiD
  • Fixed a compartment mismatch bug in plug-in code
  • Fixed a crash trying to get a nonexistent property.
  • Improved MediaRecorder's observer safety.
  • Fixed a crash related to document history.
      Changes/fixes:
      • Fixed certain network errors not displaying.
      • Fixed network error page styling.
      • Fixed the writing of DOM storage data to tabs (should solve the "tabs not loading their contents" issue when migrating a profile and some other situations).
      • Disabled downloadable font unicode-ranges on non-Windows platforms.
      • Added a Google Fonts user-agent override for non-Windows platforms so they don't send unicode-ranged composite fonts (Feature detection? Google apparently still doesn't know what that is).
      • Re-enabled the reporting of CSS errors to the console by default to prevent issues with some extensions who rely on this (e.g. Stylish).
      • Fixed and updated preferences for location bar suggestions.
      • Fixed several x64-specific issues in memory allocation code (regression fix).
      • Fixed timer issues when resuming a computer from stand-by (regression fix).
      • Fixed a number of branding and textual issues in the browser.
      • Fixed prompting for the saving of off-line data (previously always allowed without prompting).
      • Fixed a layout regression that would cause block elements following left floats to not wrap to the next line if there wasn't enough clearance.
      • Fixed a mismatch in Firefox extension compatibility-mode installation where Firefox extensions served by addons.mozilla.org would be marked incompatible when trying to install.
      Minimum system Requirements (Windows):
      • Windows Vista/Windows 7/8/10/Server 2008 or later
      • Windows Platform Update (Vista/7) strongly recommended
      • A processor with SSE2 instruction support
      • 256 MB of free RAM (512 MB or more recommended)
      • At least 150 MB of free (uncompressed) disk space
      Pale Moon includes both 32- and 64-bit versions for Windows:

      Update

      To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window.  Select About Pale Moon > Check for Updates.




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Tuesday, December 13, 2016

      Mozilla Firefox Version 50.1.0 Released with Critical Security Updates


      FirefoxMozilla sent Firefox Version 50.1.0 to the release channel today.  The update includes four (4) Critical, six (6) High and three (3) Moderate updates.  No additional changes are indicated in the release notes.  Firefox ESR was updated to version 45.6.0.

      The next scheduled release is January 23, 2017 (5 week cycle with release for critical fixes as needed).

      Security Fixes:


      Critical
      High

      Moderate

      Update

      To get the update now, select "Help" from the Firefox menu, then pick "About Firefox."  Mac users need to select "About Firefox" from the Firefox menu. If you do not use the English language version, Fully Localized Versions are available for download.

        References




        Remember - "A day without laughter is a day wasted."
        May the wind sing to you and the sun rise in your heart...




        Microsoft Security Bulletin Release for December, 2016


        As this is the second Tuesday of the month, there will be one security monthly rollup for Windows 7 and 8.1 as well as Server 2008 and 2012.  The details of the updates included are listed below.

        Reminder:  After the January 2017 Update Tuesday release, bulletins will be eliminated and the information will only be available from the new Security Updates Guide which includes the ability to view and search security vulnerability information in a single online database. The guide is described as a "portal" by the MSRC Team in Furthering our commitment to security updates.

        December Security Update Details:

        Microsoft released twelve (12) bulletins.  Six (6) bulletins are identified as Critical and six (6) rated Important in severity

        The updates address vulnerabilities in Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Microsoft Office Services and Web Apps, .NET Framework and Adobe Flash Player for Windows 8.1 and above. 

        Addressed in the updates are Remote Code Execution, Elevation of Privilege and Information Disclosure.

        Information about the update for Windows 10 is available at Windows 10 update history with #KB3206632 for 1607, #KB3205386 for 1511 and #KB3205853 for RTM. 

        Critical:
        • MS16-144 -- Cumulative Security Update for Internet Explorer (3204059)
        • MS16-145 -- Cumulative Security Update for Microsoft Edge (3204062)
        • MS16-146 -- Security Update for Microsoft Graphics Component (3204066)
        • MS16-147 -- Security Update for Microsoft Uniscribe (3204063)
        • MS16-148 -- Security Update for Microsoft Office (3204068)
        • MS16-154 -- Security Update for Adobe Flash Player (3209498)
        Important:
        • MS16-149 -- Security Update for Microsoft Windows (3205655)
        • MS16-150 -- Security Update for Secure Kernel Mode (3205642)
        • MS16-151 -- Security Update for Windows Kernel-Mode Drivers (3205651)
        • MS16-152 -- Security Update for Windows Kernel (3199709)
        • MS16-153 -- Security Update for Common Log File System Driver (3207328)
        • MS16-155 -- Security Update for .NET Framework (3205640) 

          Additional Update Notes

          • Adobe Flash Player -- For Windows Server 2012, Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10, and Windows 10 Version 1511, Adobe Flash Player is now a security bulletin rather than a security advisory and is included with the updates as identified above.
          • MSRT -- Microsoft released an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center. 
          • Windows 10 -- A summary of important product developments included in each update, with links to more details is available at Windows 10 Update History. The page will be regularly refreshed, as new updates are released.

          References


            Remember - "A day without laughter is a day wasted."
            May the wind sing to you and the sun rise in your heart...