Updating Firefox is highly recommended
Posted Oct 10, 2024 16:06 UTC (Thu)
by NightMonkey (guest, #23051)
[Link] (2 responses)
You are not authorized to access bug 1923344. To see this bug, you must first log in to an account with the appropriate permissions. "
*Sigh* Posted Oct 10, 2024 17:15 UTC (Thu)
by atai (subscriber, #10977)
[Link] (7 responses)
Posted Oct 10, 2024 17:21 UTC (Thu)
by mb (subscriber, #50428)
[Link] (2 responses)
Posted Oct 11, 2024 11:35 UTC (Fri)
by parametricpoly (subscriber, #143903)
[Link] (1 responses)
Posted Oct 25, 2024 22:24 UTC (Fri)
by mrugiero (guest, #153040)
[Link]
Posted Oct 10, 2024 17:36 UTC (Thu)
by viro (subscriber, #7872)
[Link]
Posted Oct 10, 2024 17:59 UTC (Thu)
by geofft (subscriber, #59789)
[Link] (2 responses)
Posted Oct 11, 2024 1:29 UTC (Fri)
by tschoerbi (subscriber, #88015)
[Link]
Posted Oct 11, 2024 9:03 UTC (Fri)
by kelvin (guest, #6694)
[Link]
There's a separate project which tracks the amount of Rust in Firefox (https://4e6.github.io/firefox-lang-stats/), and it currently has Rust at 11.7%. The other systems languages are C at 13.8%, and C++ at 26.7%.
I don't know why there's a difference to the github numbers, but maybe Firefox is developing cargo crates which reside outside the gecko-dev repository.
Posted Oct 11, 2024 2:07 UTC (Fri)
by randomluser (guest, #173956)
[Link] (1 responses)
Posted Oct 11, 2024 10:25 UTC (Fri)
by mss (subscriber, #138799)
[Link]
Posted Oct 11, 2024 11:39 UTC (Fri)
by parametricpoly (subscriber, #143903)
[Link] (4 responses)
"SeaMonkey 2.53.19 uses the same backend as Firefox and contains the relevant Firefox 60.8 security fixes."
"Additional important security fixes up to Current Firefox 115.14 and Thunderbird 115.14 ESR plus many enhancements have been backported. We will continue to enhance SeaMonkey security in subsequent 2.53.x beta and release versions as fast as we are able to."
The delta between the last two releases is over 5 months. So I guess Seamonkey users get these patches in March or April 2025?
Posted Oct 11, 2024 22:58 UTC (Fri)
by remicardona (guest, #99141)
[Link] (3 responses)
Posted Oct 12, 2024 5:07 UTC (Sat)
by roc (subscriber, #30627)
[Link] (1 responses)
Posted Oct 12, 2024 5:10 UTC (Sat)
by roc (subscriber, #30627)
[Link]
Posted Oct 12, 2024 10:38 UTC (Sat)
by parametricpoly (subscriber, #143903)
[Link]
Posted Oct 13, 2024 16:05 UTC (Sun)
by wx (guest, #103979)
[Link] (3 responses)
Does anyone have a fix or workaround?
Posted Oct 13, 2024 20:00 UTC (Sun)
by mathstuf (subscriber, #69389)
[Link]
Posted Nov 1, 2024 13:14 UTC (Fri)
by sammythesnake (guest, #17693)
[Link] (1 responses)
I presume there's some kind of mechanism that FF uses to tell the WM it would like to inhibit the screensaver, but at the least it's the WM's job to gate that request and ensure it doesn't override the user's intentions for their device...
Posted Nov 1, 2024 16:43 UTC (Fri)
by mathstuf (subscriber, #69389)
[Link]
Access Denied
Firefox is Rust based, right?
Firefox is Rust based, right?
If you read daroc's comment, you can see that the vulnerability was in C++ code.
Firefox is Rust based, right?
Firefox is Rust based, right?
Firefox is Rust based, right?
Firefox is Rust based, right?
Servo appears to have come back to life but that life is outside Mozilla.
Firefox is Rust based, right?
Firefox is Rust based, right?
about:config mitigation?
I wonder whether disabling JavaScript JIT (about:config mitigation?
javascript.options.baselinejit=false
) would mitigate any practical exploit here since achieving the required memory layout with just the JavaScript interpreter is AFAIK pretty hard.
What about Seamonkey?
What about Seamonkey?
What about Seamonkey?
What about Seamonkey?
What about Seamonkey?
Breaks screensaver inhibition
Breaks screensaver inhibition
Breaks screensaver inhibition
Breaks screensaver inhibition