Forum Thread: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
PSI

This thread has been marked as locked.
ceridgac Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Member 18th Jan, 2013 20:08
Ranking: 0
Posts: 4
User Since: 29th Dec, 2007
System Score: N/A
Location: US
Pale Moon 15 was upgraded to version 15.4.0.4762 one week ago. As of 2013-Thu-17-Jan, PSI indicates Pale Moon is insecure and recommends an upgrade to Pale Moon version 15.4. Pale Moon is already at version 15.4. Reinstallation of Pale Moon with the new, current version still indicates it it insecure by PSI, whether it is updated through PSI or directly from the Moonchild Website. Version 15.4.0.4762 is version 15.4. What gives here?


Maurice Joyce RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Handling Contributor 18th Jan, 2013 21:51
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
What path is PSI showing to the vulnerability?

FINDING A FILE PATH USING PSI

VERSION 2


From the DASHBOARD page click on SCAN RESULTS.

1. This will list all your programmes with a + to the left of each programme.
2. Click the + sign next to the item that U want help with.
3. This will reveal the path under DETECTED INSTANCES.
4. Below DETECTED INSTANCES you will see this You can double click this row for additional information & options>double click it>a box will appear>look to the RIGHT & U will see TROUBLESHOOT REPORT in BLUE writing under the heading TOOLBOX> click TroubleShoot Report & it will reveal some information in a box>highlight the information revealed from ---START--- to ---END--- & copy it (CTRL+C) then post it to the Forum (CTRL+V)

VERSION 3
This version does not have such an easy method to publish the path.

Open PSI>once open select Show Programs.
U will now see a page full of programme icons or a list.
Right click on the programme in error>select Show Details - that will open a box showing the path & version number of the offending file.
U now have 2 options:
1. Write down the exact file path & install version - return to the Forum & type that information.
2. Take a screen shot & publish that.

Last Reviewed 20:51 18/01/2013

--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.404
16 GB RAM
IE & Edge Only
Was this reply relevant?
+0
-0
ceridgac RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Member 19th Jan, 2013 06:25
Score: 0
Posts: 4
User Since: 29th Dec 2007
System Score: N/A
Location: US

Per Maurice's request, the following is included from the PSI Scan Results:

---START---

Program Name:
Pale Moon 15.x

Security State:
Insecure

Download Link:
http://dl.secunia.com/SPS/PaleMoon_15.4__32-bit_SP...

Instances Found:
C:\Program Files (x86)\Pale Moon\palemoon.exe, version: 15.4.0.4762

Last System Scan (localtime):
18. Jan 2013, 11:50

Operating System:
Microsoft Windows 7, Microsoft Windows 7

---END---

Now I'm confused... Should Secunia's exe file name (see above) match Pale Moon's, or does the file name contain Pale Moon Version 15.4.0.4762? The installation of Pale Moon on my machine was acquired through the normal upgrade path via the 'Help' menu option (in the browser), and then selecting 'About Pale Moon'. The dialogue box allows a check for an upgrade, followed by a subsequent download and installation directly from the Moonchild Website, which is how I usually upgrade my browsers.

- Gary (ceridgac)

Was this reply relevant?
+0
-0

layohei

RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
[+]
This reply has been deleted
Maurice Joyce RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Handling Contributor 19th Jan, 2013 10:03
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Gary,
Bit confused as well. That looks OK to me.

I assume you have tried a reboot & full PSI rescan?

If you have hopefully Secunia Support will comment or you can email them & ask them to look at this thread for you.

--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.404
16 GB RAM
IE & Edge Only
Was this reply relevant?
+0
-0
ceridgac RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Member 19th Jan, 2013 17:51
Score: 0
Posts: 4
User Since: 29th Dec 2007
System Score: N/A
Location: US
Hi Maurice,

Yes, I've rebooted, re-downloaded and reinstalled Pale Moon multiple times (even into an alternate location), re-scanned using PSI Version 2, etc. I now believe that perhaps the PSI agent has an issue with the way it compares the installed program with the naming convention it uses to establish validity with the program's version.

- Gary
Was this reply relevant?
+0
-0
Maurice Joyce RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Handling Contributor 19th Jan, 2013 18:19
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Gary,
Note this thread - I think something is amiss.

https://secunia.com/community/forum/thread/show/13...

Secunia Support will not be around until Monday to look at it for you.



--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.404
16 GB RAM
IE & Edge Only
Was this reply relevant?
+0
-0
This user no longer exists RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Secunia Official 21st Jan, 2013 14:58
Hi

We corrected the version rule so that it doesn't loop the update after a restart of the PSI interface.

Thank you for reporting the issue.
ceridgac RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Member 22nd Jan, 2013 00:50
Score: 0
Posts: 4
User Since: 29th Dec 2007
System Score: N/A
Location: US
Thanks to all for their support. That fixed the issue.

- Gary

Was this reply relevant?
+0
-0
Maurice Joyce RE: Secunia PSI Indicates That Fully Patched Pale Moon Is Insecure
Handling Contributor 22nd Jan, 2013 10:44
Score: 12325
Posts: 9,575
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Gary,
Please to see it is fixed. You may have noticed we have an active spammer on the Forum. I will lock this thread to protect your mail box from spam mail updates.

It can always be unlocked on request by emailing support@secunia.com


--
Maurice

Microsoft Surface 4 Intel i7 64Bit
Windows 10 Pro version 1809 Build 17763.404
16 GB RAM
IE & Edge Only
Was this reply relevant?
+0
-0

This thread has been marked as locked.