Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

1/11/2010
02:14 PM
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Firefox 3.6 Release Candidate Available

After being delayed last month, Firefox 3.6 is almost ready.

Mozilla on Sunday said that the Firefox 3.6 release candidate is now available for downloading.

Release candidate builds are supposed to be less buggy than beta builds but may have a few lingering compatibility and stability issues.

Firefox 3.6, an update from the current stable version 3.5.7, was suppose to be made available in Q4 2009, but Mozilla pushed back its target release date last month.

The next major Firefox release, version 4.0, was also pushed back until late 2010 or early 2011, with a beta due this summer.

Firefox 4.0 includes a project called Electrolysis, which will launch each tab window under a separate process, an innovation that first appeared in Google Chrome. This will help make Firefox more secure and more stable. Firefox 4.0 may also bring user interface changes.

Mozilla faces a rising challenge from Google Chrome, which by NetApplications' measure last month passed Apple's Safari browser in global market share. That challenge is magnified by the increasing importance of Web browsing on mobile devices, where Firefox is not as well-established as it is on the desktop and is unavailable on devices like the iPhone.

Nonetheless, Firefox's growth appears to be healthy. "In the 4 months leading up to the holiday season, Firefox added 22.8 million active daily users," said Mozilla's "analytics guru" Blake Cutler in a blog post on Friday. "During that same period last year, Firefox added 16.4 million users."

The official release of Firefox 3.6 should happen before the end of the month, assuming no show-stopping bugs are found in the release candidate.

Version 3.6 allows users to change the way Firefox looks, thanks to built-in support for Personas, a Mozilla project that allows easy customization of the browser's appearance.

It features improved JavaScript performance, automatic detection of outdated plugins, a "full screen" menu option for videos embedded using the HTML5 video tag, support for location-aware browsing on some laptops and mobile devices, and support for the the Web Open Font Format, known as WOFF.

Firefox 3.6 will no longer load third-party components installed in its internal components directory, a change that promotes stability and security. It also introduces support for a number of new features for Web developers, such as the ability to detect device orientation and accelerometer support in Mac laptops.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23381
PUBLISHED: 2021-04-18
This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
CVE-2021-23374
PUBLISHED: 2021-04-18
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
CVE-2021-23375
PUBLISHED: 2021-04-18
This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
CVE-2021-23376
PUBLISHED: 2021-04-18
This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
CVE-2021-23377
PUBLISHED: 2021-04-18
This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.