Risk
6/23/2010
04:47 PM
50%
50%

Firefox 3.6.4 Adds Crash Protection

Third-party plug-ins will be isolated when they crash or freeze, allowing the browser to continue running with the option to restart plug-in content by refreshing the page

Mozilla has released a Firefox security and stability update that adds crash protection to the popular Web browser.

Firefox 3.6.4 isolates third-party plug-ins when they crash or freeze. The new feature will be particularly helpful when using video-watching plug-ins, such as Adobe Flash, Microsoft Silverlight and Apple Quicktime.

Crash protection is available for Windows and Linux systems only. The feature will be available for Mac OS X when Firefox 4 ships, Mozilla said in its blog.

As many as one in three Firefox crashes are caused by problems with third-party plug-ins, according to Mozilla. The new feature will allow the browser to keep running while portions of a Website controlled by the plug-in are disabled. Refreshing the page can restart plug-in content.

Support for Mac OS X has been delayed because the new feature requires major changes to Firefox on the Apple platform, Mozilla said.

In releasing crash protection, Mozilla is playing catch up with Google Chrome, which has had crash protection since it was first released in 2008.

The five most popular browsers are Microsoft Internet Explorer, Firefox, Apple Safari, Chrome and Opera. IE remains the most widely used browser, accounting for nearly 60% of the market in May, according to Net Applications.

However, IE's share has been falling. The latest figures from Net Applications showed that number three Chrome has continued to gain usage momentum, rising to more than 7% of the market in May. Firefox is number two with a more than 24% share.

As the defacto browser for Macs, fourth-place Safari's growth is expected to continue rising due to sales of the iPad, which are at more than 3 million units since its release in April.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
8 Key Building Blocks for Enterprise Network Defense
Networks are changing rapidly -- and so are strategies for protecting them. This Tech Digest looks at the fundamentals for the next-gen environment.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In this episode of Dark Reading Radio, veteran CISOs will share their experience and insight into how organizations can get the best bang for their security buck.