LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: Corrine on April 18, 2023, 01:07:01 PM

Title: Pale Moon Version 32.1.1 Released with Security Updates
Post by: Corrine on April 18, 2023, 01:07:01 PM
Pale Moon has been updated to version 32.1.1.  This is a bugfix and security release.

Changes/Fixes:


Implementation notes:


        Previously, these cache files, while in the O.S. temporary file location (%TEMP% or /tmp), would not be consistently cleaned up, potentially causing privacy issues if persisted. This was changed to using auto-cleaning anonymous temp files, improving user privacy and relying less on the O.S. or user performing cleanup of temporary file storage. Thanks to Sandra for pointing this out and providing the patch.

Notes:

DiD This means that a fix is "Defense-in-Depth": It is a fix that does not apply to a (potentially) actively exploitable vulnerability in Pale Moon, but prevents future vulnerabilities caused by the same code, e.g. when surrounding code changes, exposing the problem, or when new attack vectors are discovered.

Rejected security patches: This means that patches were theoretically applicable to our code but considered undesirable, which could be due to unwanted changes in behavior, known regressions caused by the patches, or unnecessary risks for stability, security or privacy.

Pale Moon includes both 32- and 64-bit versions for Windows: Pale Moon for Windows downloads (https://www.palemoon.org/download.shtml?fbclid=IwAR2YsYQ2YAbSVgyFl_bk5GfMJyNy1FfvPYK9MYSCSanIHmx9U7ZspxJeImo). To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window.  Select About Pale Moon > Check for Updates.

Release Notes (https://www.palemoon.org/releasenotes.shtml)
Release Cycle (https://developer.palemoon.org/docs/release-engineering/)