Page 1 of 1

Yet another reason to never let applications auto-update...

Posted: Tue Feb 09, 2016 9:24 pm
by barbaz

Re: Yet another reason to never let applications auto-update

Posted: Tue Feb 09, 2016 11:00 pm
by Thrawn
The auto-update library depends on WebKit?! Why?!

Re: Yet another reason to never let applications auto-update

Posted: Wed Feb 10, 2016 3:42 pm
by therube
The auto-update library depends on WebKit?! Why?!
Have you ever run, what should be stand-alone applications, that do embed the IE rendering engine within, thereby making that application susceptible to IE exploits.

Image

Mozilla [had] run into similar a long time back, Bug 435743 - Extension manager should load updates served from https signed by any installed CA.

And Malwarebytes has something going on currently, Malwarebytes Anti-Malware Vulnerability Disclosure.

And Mozilla may currently have an issue with "fonts", Vulnerability Spotlight: Libgraphite Font Processing Vulnerabilities.

Re: Yet another reason to never let applications auto-update

Posted: Wed Feb 10, 2016 4:35 pm
by barbaz
therube wrote:Have you ever run, what should be stand-alone applications, that do embed the IE rendering engine within, thereby making that application susceptible to IE exploits.

Image
... :!:
therube wrote:And Mozilla may currently have an issue with "fonts", Vulnerability Spotlight: Libgraphite Font Processing Vulnerabilities.
According to that link, Mozilla doesn't anymore, but latest stable release SeaMonkey does...

Re: Yet another reason to never let applications auto-update

Posted: Wed Feb 10, 2016 11:09 pm
by Thrawn
therube wrote:Have you ever run, what should be stand-alone applications, that do embed the IE rendering engine within, thereby making that application susceptible to IE exploits.
Yes, it's called Windows Explorer, but I would have thought that Apple would have known better than that.

Re: Yet another reason to never let applications auto-update

Posted: Wed Feb 10, 2016 11:14 pm
by barbaz
Sparkle isn't made by Apple.

Re: Yet another reason to never let applications auto-update

Posted: Thu Feb 11, 2016 4:31 am
by Thrawn
Oh, true, I missed that.