Firefox Version 50.0.2 Released to Address Critical Zero-Day Vulnerability

Started by Corrine, November 30, 2016, 11:05:22 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Corrine

Mozilla sent Firefox Version 50.0.2 to the release channel today to address a critical zero-day vulnerability in the wild.  Firefox ESR was updated to version 45.5.1.  The update includes only the one critical update, Firefox SVG Animation Remote Code Execution.

Additional information about the vulnerability here:  Vulnerability Note VU#791496 - Mozilla Firefox SVG animation nsSMILTimeContainer use-after-free vulnerability.

Note:  As explained in the Pale Moon forum announcement, although significantly diverted from Mozilla development, the question arose as to whether Pale Moon is also vulnerable.  After evaluation, it was reported that it is extremely unlikely that Pale Moon is vulnerable to this exploit.




Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

plodr

Thanks. I updated all four ESR versions earlier today with no problems.
Chugging coffee and computing!

Corrine

Quote from: Corrine on November 30, 2016, 11:05:22 PM
Note:  As explained in the Pale Moon forum announcement, although significantly diverted from Mozilla development, the question arose as to whether Pale Moon is also vulnerable.  After evaluation, it was reported that it is extremely unlikely that Pale Moon is vulnerable to this exploit.
Twitter message from PaleMoon:
QuoteDespite this, we'll still be releasing a DiD patched update on Dec 2nd that fixes the crash at the root of this.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

plodr

Thanks. I grabbed the new version on my portable Palemoon this morn.
Chugging coffee and computing!