Firefox のソースコードを元に、軽量化、高速化を志向するブラウザ
『Pale Moon』 に関する話題をどうぞ
公式ホームページ
http://www.palemoon.org/
Archived versions
http://www.palemoon.org/archived.shtml
日本語のランゲージパックは諸事情により非公開になりました
以下のプレリリース版を利用して下さい
https://github.com/JustOff/pale-moon-localization/releases
前スレ
Pale Moon Part13
https://egg.5ch.net/test/read.cgi/software/1534856140/
Pale Moon Part14
■ このスレッドは過去ログ倉庫に格納されています
2019/06/19(水) 16:15:44.07ID:9FeTxod80
2019/07/25(木) 22:21:21.18ID:ZbVRwCjH0
Pale Moon: Release notes
v28.6.1 (2019-07-25)
This is security and bugfix update.
Changes/fixes:
Improved handling of FTP resource loading (allow save-as and cater to some FTP-based browsing).
Added a preference (security.block_ftp_subresources) to allow users to completely bypass the blocking of FTP subresources if required for their environment, if the improvements made in this release do not suffice.
Added blocking of authentication-locked cross-origin image subresources by default to prevent spurious auth prompts.
A preference (network.auth.subresource-http-img-XO-auth) was added to allow users to bypass this blocking if required for their environment.
Changed the behavior of file: URIs to treat each URI as a unique origin. This prevents cross-file access from scripting.
A preference (security.fileuri.unique_origin) was added to allow users to relax this restriction if required for their environment.
Implemented a revised version of http2PushedStream to address some thread safety issues.
Aligned browser behavior with mainstream regarding inner window behavior when domain is manipulated.
Backed out a 28.5.* patch for causing multiple issues in the UI and web content.
Updated NSS to 3.41.2 (custom) to pick up several upstream fixes.
Fixed a type confusion issue in JavaScript Arrays. (DiD)
Added a fix for cross-thread access of Necko. (DiD)
Added a port safety check for Alternative Services.
Implemented fixes for applicable security issues: CVE-2019-11719, CVE-2019-11711, CVE-2019-11715, CVE-2019-11717, CVE-2019-11714 (DiD), CVE-2019-11729 (DiD), CVE-2019-11727 (DiD), CVE-2019-11730 (DiD), CVE-2019-11713 (DiD) and
several networking and memory-safety hazards that do not have CVE numbers.
v28.6.1 (2019-07-25)
This is security and bugfix update.
Changes/fixes:
Improved handling of FTP resource loading (allow save-as and cater to some FTP-based browsing).
Added a preference (security.block_ftp_subresources) to allow users to completely bypass the blocking of FTP subresources if required for their environment, if the improvements made in this release do not suffice.
Added blocking of authentication-locked cross-origin image subresources by default to prevent spurious auth prompts.
A preference (network.auth.subresource-http-img-XO-auth) was added to allow users to bypass this blocking if required for their environment.
Changed the behavior of file: URIs to treat each URI as a unique origin. This prevents cross-file access from scripting.
A preference (security.fileuri.unique_origin) was added to allow users to relax this restriction if required for their environment.
Implemented a revised version of http2PushedStream to address some thread safety issues.
Aligned browser behavior with mainstream regarding inner window behavior when domain is manipulated.
Backed out a 28.5.* patch for causing multiple issues in the UI and web content.
Updated NSS to 3.41.2 (custom) to pick up several upstream fixes.
Fixed a type confusion issue in JavaScript Arrays. (DiD)
Added a fix for cross-thread access of Necko. (DiD)
Added a port safety check for Alternative Services.
Implemented fixes for applicable security issues: CVE-2019-11719, CVE-2019-11711, CVE-2019-11715, CVE-2019-11717, CVE-2019-11714 (DiD), CVE-2019-11729 (DiD), CVE-2019-11727 (DiD), CVE-2019-11730 (DiD), CVE-2019-11713 (DiD) and
several networking and memory-safety hazards that do not have CVE numbers.
2019/07/25(木) 22:22:56.50ID:ZbVRwCjH0
DiD This means that the fix is "Defense-in-Depth": It is a fix that does not apply to a (potentially) actively exploitable vulnerability in Pale Moon,
but prevents future vulnerabilities caused by the same code, e.g. when surrounding code changes, exposing the problem, or when new attack vectors are discovered.
but prevents future vulnerabilities caused by the same code, e.g. when surrounding code changes, exposing the problem, or when new attack vectors are discovered.
■ このスレッドは過去ログ倉庫に格納されています
ニュース
- 【実況】ショートスリーパー堀大輔の7日間LIVE 本日最終日★36 [爆笑ゴリラ★]
- 都立高の教諭が生徒2人と窃盗未遂疑いで逮捕「おりんは高く売れる…」などと助言か「肝試し的な感覚だった」と供述 [ポンコツ★]
- 【実況】ショートスリーパー堀大輔の7日間LIVE 本日最終日★35 [爆笑ゴリラ★]
- 【文春】TBSがひた隠すVIVANT・福澤克雄監督(62)の“骨折パワハラ”《全治1カ月も激アマ処分》 [Ailuropoda melanoleuca★]
- 「ゼロ打ちで勝つ準備をしていたのに」 スター戦術押し切れず デニー(氏)人気の衰退に気付くも時遅し (沖縄タイムス) [少考さん★]
- 「洗濯物を回収するため」ベランダで全裸、公然わいせつ容疑で男逮捕 歩行中の女性が目撃 兵庫 ★2 [少考さん★]
- 【訃報】19歳の四国電力社員、パワハラ被害で飛び降り自殺、遺書には「俺を生んでくれてありがとう」 [339035499]
- 客「おまんじゅう5個のを5個」、店「5個入りのお饅頭を5つ、25個ですね」、客「5個のを2つだよ💢」 [256556981]
- 【正論】レジェンドマンガ家「編集にみせて、なんか言われたから訂正して、それで売れなかったら責任って取ってくれんの?」 [591180291]
- ディランマッケイの不思議なお🏡
- 高市首相「秋のAPEC首脳会議楽しみ!😊」 ロシア「高市との会談お断り」 中国「高市との会談お断り」 [668024367]
- ジャップ「ハワイ旅行楽しいです^^」 高市早苗「そうわよ!」 [592058334]