Mozilla Closes Down Critical Security Holes
The Mozilla Foundation has just released Firefox version 2.0.0.10 which resolves three critical vulnerabilities – but new issues have already reared their ugly heads.
One of the most serious vulnerabilities concerned handling of .jar files. An error in the Jar protocol implementation allowed cross-site scripting attacks on filters and other safeguards to grab login information and other data. Another scenario describes attacks with carefully crafted archives. Redirects allowed attackers to exploit the vulnerability. The second error to have been removed was exploitable by setting the "window.location" to redirect HTTP headers and thus launch cross-site scripting attacks.
The third error originated from a memory management bug which attackers could exploit to crash the browser or execute malicious code on the victim’s system. These vulnerabilities also affect Mozilla Seamonkey, a new version of which (1.1.7) will become available in the next few days.
But shortly after version 2.0.0.10 of Firefox was released, the next crop of bugs was identified. US-based developer Kevin Han has reported a bug that prevents the browser from displaying graphics embedded using Javascript. The new version responds to the "canvas.drawImage()" instruction with an error message of "NS_ERROR_NOT_AVAILABLE"; instead of displaying vector graphics, the method now draws pixel images in them.
Despite the new bug, the Firefox developers still advise users to update to the new version of the browser. The Mozilla Foundation servers have versions in various languages with distribution packages due to follow in the next few days.
Issue 41: Linux Shell Handbook 2021 Edition/Special Editions
Buy this issue as a PDF
News
-
Apple M1 Hardware Support to be Merged into Linux Kernel 5.13
Linux users will be able to install their favorite distribution on Apple’s M1-based hardware.
-
KDE Launches the Qt 5 Patch Collection
To support and maintain a stable Qt 5 for KDE Gears and Frameworks, KDE will maintain a patch collection.
-
Linux Creator Warns Next Kernel Could be Delayed
Linus Torvalds has issued concern about the size of kernel 5.12 and possible delays for its release.
-
System76 Updates its Pangolin Laptop
System76 has released a much-anticipated AMD version of their most popular laptop, the Pangolin.
-
New Debian-Based Distribution Arrives on the Market
TelOS is a new Debian-based Linux distribution with a customized, touch-screen-ready KDE Plasma 5 desktop.
-
System76 Releases New Thelio Desktop
One of the most ardent supporters of open source hardware has released a new desktop machine for home or office.
-
Mageia 8 Now Available with Linux 5.10 LTS
The latest release of Mageia includes improved graphics support for both AMD and NVIDIA GPUs.
-
GNOME 40 Beta has been Released
Anyone looking to test the beta for the upcoming GNOME 40 release can now do so.
-
OpenMandriva Lx 4.2 has Arrived
The latest stable version of OpenMandriva has been released and offers the newest KDE desktop and ARM support.
-
Thunderbird 78 Ported to Ubuntu 20.04
The Ubuntu developers have made the decision to port the latest release of Thunderbird to the LTS version of the platform.