Mozilla Closes Down Critical Security Holes
The Mozilla Foundation has just released Firefox version 2.0.0.10 which resolves three critical vulnerabilities – but new issues have already reared their ugly heads.
One of the most serious vulnerabilities concerned handling of .jar files. An error in the Jar protocol implementation allowed cross-site scripting attacks on filters and other safeguards to grab login information and other data. Another scenario describes attacks with carefully crafted archives. Redirects allowed attackers to exploit the vulnerability. The second error to have been removed was exploitable by setting the "window.location" to redirect HTTP headers and thus launch cross-site scripting attacks.
The third error originated from a memory management bug which attackers could exploit to crash the browser or execute malicious code on the victim’s system. These vulnerabilities also affect Mozilla Seamonkey, a new version of which (1.1.7) will become available in the next few days.
But shortly after version 2.0.0.10 of Firefox was released, the next crop of bugs was identified. US-based developer Kevin Han has reported a bug that prevents the browser from displaying graphics embedded using Javascript. The new version responds to the "canvas.drawImage()" instruction with an error message of "NS_ERROR_NOT_AVAILABLE"; instead of displaying vector graphics, the method now draws pixel images in them.
Despite the new bug, the Firefox developers still advise users to update to the new version of the browser. The Mozilla Foundation servers have versions in various languages with distribution packages due to follow in the next few days.
Issue 268/2023
Buy this issue as a PDF
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Find SysAdmin Jobs
News
-
Escuelas Linux 8.0 is Now Available
Just in time for its 25th anniversary, the developers of Escuelas Linux have released the latest version.
-
LibreOffice 7.5 has Arrived Loaded with New Features and Improvements
The favorite office suite of the Linux community has a new release that includes some visual refreshing and new features across all modules.
-
The Next Major Release of Elementary OS Has Arrived
It's been over a year since the developers of elementary OS released version 6.1 (Jólnir) but they've finally made their latest release (Horus) available with a renewed focus on the user.
-
KDE Plasma 5.27 Beta Is Ready for Testing
The latest beta iteration of the KDE Plasma desktop is now available and includes some important additions and fixes.
-
Netrunner OS 23 Is Now Available
The latest version of this Linux distribution is now based on Debian Bullseye and is ready for installation and finally hits the KDE 5.20 branch of the desktop.
-
New Linux Distribution Built for Gamers
With a Gnome desktop that offers different layouts and a custom kernel, PikaOS is a great option for gamers of all types.
-
System76 Beefs Up Popular Pangolin Laptop
The darling of open-source-powered laptops and desktops will soon drop a new AMD Ryzen 7-powered version of their popular Pangolin laptop.
-
Nobara Project Is a Modified Version of Fedora with User-Friendly Fixes
If you're looking for a version of Fedora that includes third-party and proprietary packages, look no further than the Nobara Project.
-
Gnome 44 Now Has a Release Date
Gnome 44 will be officially released on March 22, 2023.
-
Nitrux 2.6 Available with Kernel 6.1 and a Major Change
The developers of Nitrux have officially released version 2.6 of their Linux distribution with plenty of new features to excite users.