EDGE 2015 is starting in

Find out more EDGE 2015
Mozilla delivers silent updating with Firefox 12 release

Mozilla delivers silent updating with Firefox 12 release

Patches 14 security bugs in the desktop browser, 19 in the mobile version


Mozilla today released Firefox 12, patching 14 security bugs in the browser and moving it one step closer to matching rival Chrome in silent updating.

The latest in the line of updates that have rolled off the Mozilla development line every six weeks since mid-2011, Firefox 12 fixed seven vulnerabilities labeled "critical," the highest threat ranking in Mozilla's four-step scoring, four bugs tagged "high" and three pegged "moderate."

Mozilla also patched 19 other bugs, all critical, in the mobile edition of Firefox, which runs on the Android platform.

Among the 14 desktop vulnerabilities, Mozilla patched three that could be used by hackers in cross-site scripting (XSS) attacks, one that applied only to Windows Vista and Windows 7 PCs with hardware acceleration disabled and another in image rendering done by the WebGL 3D standard.

Two of the bugs were reported by security researchers at rivals Google and Opera Software. The Google engineer also notified Mozilla of all 19 vulnerabilities in the FreeType library that affected the mobile version of the browser.

Unlike Google, Mozilla does not call out bounties it's paid to outside researchers for reporting vulnerabilities, even though Mozilla does have a reward program.

As usual, Mozilla did not explicitly say that all the flaws could be exploited, but instead hedged with its traditional phrasing of, "We presume that with enough effort at least some of these could be exploited to run arbitrary code."

Eleven of the 14 bugs were also patched in Firefox ESR, or Extended Support Release, the longer-lived edition designed for enterprises that don't want to update workers' machines every few weeks.

The current version of Firefox ESR is based on Firefox 10, which shipped in December 2011. ESR receives only security updates during its 54-week lifespan. The first iteration of ESR won't appreciably change until November 2012, and will be supported with security patches until early February 2013.

As expected, Mozilla did not release fixes for Firefox 3.6, the 2010 browser it officially retired today.

Mozilla has been nagging Firefox 3.6 users with pleas to upgrade for weeks, and will take the unusual step of automatically upgrading them to Firefox 12 early next month.

Although Mozilla touted a total of 85 improvements for Web developers, it focused on the feature that brought the browser, at least on Windows, one step closer to true "silent" updating.

Firefox 12 skirts Windows' UAC prompt, but by clearing the highlighted box, users can restore the warning.

"Firefox simplifies the update process for Windows users by removing the user account control dialog (UAC) pop-up while maintaining the security of your system," the company said in a Tuesday blog post announcing the release of Firefox 12. "Once a user gives explicit permission to Firefox on their first installation, they will not be prompted again for subsequent releases."

Skirting UAC pushes Firefox updates further into the background on Windows Vista and Windows 7 machines; both operating system demand users' approval before installing software.

While updating Firefox to version 12 requires a click in the UAC dialog on Vista and Windows 7, that should be the last time users see the prompt.

Users can restore UAC's interruption to Firefox updates if they wish by clearing a box in the "Advanced" section of the Options window.

Mozilla has just one more component on its silent update to-do list.

That piece, now scheduled to appear in either Firefox 13, which ships June 5, or Firefox 14, slated to release July 17, will apply the update entirely in the background so that the user no longer sees an update installation progress bar.

Called "background updating" by Mozilla, the process will seem invisible to users because the update is automatically applied, then staged in a different directory or folder than the current copy of the browser. The next time Firefox is launched, the staged directory swaps places with the active directory.

Mozilla has been chasing Google's Chrome, which has featured silent, behind-the-scenes updating, since the latter's 2008 debut.

The open-source developer has been working on silent updating for nearly two years. At one point, it thought it could add the feature to Firefox 4, which shipped in March 2011, but the company abandoned work when that version was delayed several times for other reasons. And late last year, Mozilla said it was shooting for silent updating in Firefox 10, which debuted in January 2012. Those plans were also scrapped.

Windows, Mac and Linux editions of Firefox 12 can be downloaded manually from Mozilla's site. Users running Firefox 4 or later will be offered the upgrade through the browser's own update mechanism.

The next version of Firefox is scheduled to ship June 5.

Read more about browsers in Computerworld's Browsers Topic Center.

EDGE 2015:: For all the latest on EDGE 2015 including the keynote speakers visit the EDGE mini-site now

2015 ARN ICT Industry Awards: Nominations for the 2015 ARN ICT Industry Awards close on June 26. NOMINATE NOW!!!

Follow Us

Join the ARN newsletter!

Error: Please check your email address.



In Pictures: Robots that cook, clean, sing and dance
Tech Hive

In Pictures: Robots that cook, clean, sing and dance

Cooking, learning language and doing the laundry are a few of the human skills demonstrated by.real humanoid bots featured in the National Geographic movie Robots.

In Pictures: Robots that cook, clean, sing and dance
IN PICTURES: OKI Data Australia partner event (+10 photos)
Business Products

IN PICTURES: OKI Data Australia partner event (+10 photos)

OKI recently hosted its ChannelOne dealer forum for its executive series channel partners to get together and learn about the company's new high-performance ES8400 A3 multifunction series printers. After a welcome and business overview from OKI Data Australia managing director, Dennie Kawahara, delegates were given a comprehensive overview of the new product, as well as an update on the latest marketing initiatives and software solutions, before being treated to live demos and a product showcase. Partners were also given a preview of OKI’s upcoming A3 digital LED white toner printer. With more than 60 delegates attending from all over the country, the day concluded with dinner at Casa Ristorante Italiano in Sydney and several delegates also participated in a friendly game of golf the following morning.

IN PICTURES: OKI Data Australia partner event (+10 photos)

iasset.com is a channel management ecosystem that automates all major aspects of the entire sales, marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.

Show Comments