Language Selection

English French German Italian Portuguese Spanish

Firefox 10 relieves add-on updating pain

Filed under
Moz/FF

Mozilla today patched eight vulnerabilities in Firefox as it shipped the latest iteration in its rapid release schedule.

Firefox 10, sixth in the line of updates that have been rolling off the development line every six weeks since mid-2011, fixed half a dozen flaws rated "critical," Mozilla's highest threat ranking, and another two labeled "high."

One of the notable vulnerabilities addressed in Firefox 10 could open users to cross-site scripting (XSS) attacks because the browser did not properly run a security check when calling untrusted scripting objects, said Mozilla.

"The fix enables the Script Security Manager (SSM) to force security checks on all frame scripts," an accompanying advisory noted.

rest here

Release Notes




More in Tux Machines

SolydX 201411 Is a Rolling Release Alternative to Linux Mint Debian Xfce

SolydX, a Debian-based distribution that features the Xfce desktop environment and uses a rolling release model, is now at version 201411 and is ready for download. Read more

Linux-Based Beautiful Jolla Tablet Registers Fantastic Success on Indigogo

Jolla is a new tablet developed by a team of people who used to work for Nokia and it's powered by a Linux-driver operating system called Sailfish OS. The recently launched crowdfunding campaign has surpassed any expectations. Read more

WordPress 4.0.1 Updates Millions of Sites for 8 Flaws

Millions of open-source WordPress site owners received email notifications over the last 24 hours advising them of a site update. The new WordPress 4.0.1 update provides multiple security fixes and data-hardening improvements to help secure WordPress sites. The WordPress 4.0.1 update is the first incremental update for WordPress since the 4.0 release in September. The 4.0.1 update provides 23 bug fixes and an additional 8 security vulnerability fixes. Read more

V2 Of KDBUS Published For Linux Kernel Review

The second revision to the Linux kernel based D-Bus implementation is now available for review. Greg Kroah-Hartman on Thursday night posted the "v2" revision of the KDBUS implementation for providing the kernel with a new IPC implementation that resembles the existing user-space D-Bus daemon while adding extra features. Among the changes in this revision to KDBUS are exposing its control files and other information via a new kdbusfs file-system, KDBUS expects to be mounted to /sys/fs/kdbus, a new KDBUS domain is created for each time kdbusfs is mounted, and various other low-level changes. More details via the patch-set series. It's not clear yet whether KDBUS will be ready for merging in the Linux 3.19 kernel or will be held off until Linux 3.20 or longer. Read more