Jump to content

Pale Moon Version 25.2 Released with Security Updates


Corrine

Recommended Posts

Pale Moon has released version 25.2 to extend browser capabilities and implement some ES6 draft functions for web programmers. The update includes important crash fixes, bug fixes and security updates.

 

Security/privacy fixes:

  • Added a preference network.stricttransportsecurity.enabled to enable or disable the use of HSTS (HTTP Strict Transport Security), allowing users to choose between privacy and security in this matter. (hidden pref)
  • Fixed CVE-2014-1589 by whitelisting XBL bindings that may be applied to untrusted content.
    Important: extension developers should read this related thread.
  • Fixed CVE-2014-1593.
  • Mac: fixed CVE-2014-1595.
  • Fixed CVE-2014-8639 by adjusting cookie handling through proxies.
  • Fixed CVE-2014-8636.
  • Fixed several memory safety hazards that do not have CVE numbers.

 

Fixes and changes are documented in the Release Notes.

 

To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window. Select About Pale Moon > Check for Updates.

Link to comment
Share on other sites

If you use Adblock Latitude (ABL), check extensions to make sure it has updated to ABL 3.0.1 or it may not work properly (and start blocking too much) when updating to Pale Moon 25.2. This is a required update of the extension because of one of the security updates in the new version of the browser! ABL 3.0.1 is available here: https://addons.palemoon.org/extensions/privacy-and-security/adblock-latitude/

  • Like 1
Link to comment
Share on other sites

  • 2 weeks later...

Pale Moon version 25.2.1 has been released to address cookie handling through proxies causing issues for some authenticating proxies in corporate environments.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...