Jump to content

Pale Moon Version 25.3.0 Released with Security Updates


Corrine

Recommended Posts

Pale Moon has been updated to version 25.3.0 with improved features and performance as well as security updates.

 

From the Release Notes, it is noted that several security fixes are identified as DiD. This means that the fix is "Defense-in-Depth":

"It is a fix that does not apply to an actively exploitable vulnerability in Pale Moon, but prevents future vulnerabilities caused by the same code when surrounding code changes, exposing the problem."

 

Although I haven't run into any issues with PaleMoon on Windows 10 Technical Preview, note the addition of Windows 10 compatibility in executable manifests to the update.

 

Security fixes:

  • Disabled all RC4-based encryption ciphers by default.
  • Fixed several miscellaneous memory safety hazards.
  • (applicable bugs related to CVE-2015-0835 and CVE-2015-0836)
  • Fixed loading of locally stored DLL files through the internal updater. (CVE-2015-0833)
  • Fixed a potential crash point in IndexedDB. (CVE-2015-0831) DiD
  • Fixed a double-free situation when using non-default memory allocators and a 0-length XHR. (CVE-2015-0828)
  • Note: production builds of Pale Moon were never vulnerable.
  • Fixed a crash using DrawTarget in the Cairo graphics library. (CVE-2015-0824)
  • Fixed potential reading of local files through manipulation of form autocomplete. (CVE-2015-0822)
  • Fixed a potential PNG heap-overflow crash. DiD
  • Followed up on research regarding CVE-2014-8639 (see 25.2) and made cookie handling through proxies more restrictive again.

See the Release Notes for the complete list of fixes, additions and improvements.

 

To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window. Select About Pale Moon > Check for Updates.

  • Like 2
Link to comment
Share on other sites

  • 2 weeks later...

Pale Moon has been updated to version 25.3.1 to address a critical vulnerability discovered in the HP Zero Day Initiative's Pwn2Own contest. Only one vulnerability discovered applied to Pale Moon.

  • Like 2
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...