Index  | Recent Threads  | Unanswered Threads  | Who's Active  | Guidelines  | Search
 

Quick Go »
No member browsing this thread
Thread Status: Active
Total posts in this thread: 30
Posts: 30   Pages: 3   [ Previous Page | 1 2 3 ]
[ Jump to Last Post ]
Post new Thread
Author
Previous Thread This topic has been viewed 3539 times and has 29 replies Next Thread
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: Firefox 1.0.4 released 12 May 2005

Mozilla fixes Firefox flaws

Foundation responds quickly to security bug
Iain Thomson, vnunet.com 13 May 2005

Less than a week after the discovery of critical flaws in Mozilla's Firefox browser, the organisation has released a fix.

The Mozilla Foundation is urging users to upgrade their browsers to the new version 1.0.4, which is available for download immediately. Versions are available for Windows, Mac and Linux.

"We are still working to get the rest of the localisations ready and the update notifications live, but if you're in a hurry the English/US build of Firefox 1.0.4 is now available for download," said Asa Doltzer, product release manager for Firefox.

The new version fixes the security holes and includes improved dynamic HTML handling after a bug was found in version 1.0.3 of the browser.

Firefox was launched last year and is currently the second most popular browser on the market, after Microsoft's Internet Explorer. Over 2.5 million copies were downloaded from the organisation's website in March.
[May 13, 2005 4:42:35 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Mozilla Issues Patches for Firefox Installation Bugs

Mozilla Issues Patches for Firefox Installation Bugs

By Jennifer LeClaire - www.LinuxInsider.com - Part of the ECT News Network
05/12/05 10:47 AM PT

Chris Hofmann, director of engineering of Mozilla Foundation, said staying ahead of malicious code writers is a continual process for the open-source software group. "We want to continue to encourage security researchers and experts to help us improve the browser," he told LinuxInsider.

Close only counts in horseshoes. In business, close isn’t good enough. When your employees and customers are looking for information, they need a search engine that delivers pinpoint accuracy. Download a FREE 30-day trial of Verity Ultraseek and get accurate results with your enterprise search.

The Mozilla Foundation has readied security patches to thwart what security firm Secunia reported earlier this week as two "extremely critical" flaws in its Firefox browser.

Secunia said the vulnerabilities could be exploited by malicious people who wish to take control of victims' computers. Firefox executives are hoping the firm will downgrade the classification once the patches are fully distributed.

Chris Hofmann, director of engineering of Mozilla Foundation, told LinuxInsider that fixes are currently available in 12 of the 37 languages Firefox offers. Fixes for the remaining languages will be ready in the next 24-28 hours.

"We provided a workaround earlier this week. We advised users to disable the list of sites from which they allow software updates," Hofmann said. "The fix that we put out last night allows users to turn that list back on."

Reviewing the Bugs
The first problem is that "IFRAME" JavaScript URLs are not properly protected from being executed in context of another URL in the history list, Secunia said. This can be exploited to execute arbitrary HTML and script code in a user's browser session.

The second problem is input passed to the "IconURL" parameter in "InstallTrigger.install()" is not properly verified before being used. Secunia said this can be exploited to execute arbitrary JavaScript code with escalated privileges via a specially crafted JavaScript URL. Successful exploitation requires that the site is allowed to install software.

Hofmann said staying ahead of malicious code writers is a continual process for the open-source software group. "We want to continue to encourage security researchers and experts to help us improve the browser," he said. "These contributors help us create a strong architecture around the browser that will protect us from serious exploits from ever appearing."

'All-Eyes' Development Approach
Open-source software companies like Mozilla have an advantage over commercial companies, said Hofmann, because the availability of the source code opens the door for new perspectives.

"We actually have a very passionate community of developers that are working on security and privacy," he said. "When these types of reports come in, they respond very quickly to help us get the patch put together and tested and out to users."

In the browser wars, the bottom line is becoming more about security on a World Wide Web full of hackers, crackers and online thieves, according to industry watchers. Jupiter Research analyst Joe Wilcox told LinuxInsider that it remains to be seen which browser offers the best protection.

Providing Cover
"There's the argument that the open-source, all-eyes approach keeps the software more secure in the first place and provides more resources for fixing problems when they are uncovered," he said. "The commercial argument says because outsiders generally don't see the source code it's more difficult for them to uncover or generate vulnerabilities. The commercial camp says it is also able to respond faster.

All debate aside, Wilcox said it boils down to quick response times when bugs are discovered. In response, Hofmann said Mozilla is committed to that quick response with the help of its growing community.
[May 13, 2005 4:52:32 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Interesting Add-ons for Firefox

No security update yet as of 11 July 2005 for Firefox. I have been following the situation on MozillaZine at http://www.mozillazine.org/ Firefox 1.0.5 is still being tested. Meanwhile, Firefox 1.1 ('Deer Park') is still coming along. However, a new article pointed out some interesting downloads for Firefox so I decided to post to this thread.

There is a recent article titled 'Still More Cool Firefox Tools' at http://searchenginewatch.com/searchday/article.php/3518256

I have been using the Googlebar. After some experimentation, I removed some unused icons from my Firefox Navigation Toolbar (using View) and tried to move some icons from Googlebar onto it. Well, that did not work. So I deselected Googlebar to give me more space for websites, activating it only when I wanted special searches. But the tiny Search Box on the Navigation Toolbar was frustrating.

After reading the new article, I downloaded Resize Search Box. I also downloaded the Google Toolbar and customized it by activating the ‘Same Site’ search icon, so I now have the option to go to a customer support site and search within it for a phrase. Oddly, it installed as Google Toolbar, leaving me with the older Googlebar as a separate option. But I went into View and disabled both bars by default. I now have a long Search Box in Firefox and I still only need a specialized Search Bar for special purposes, not all the time.
[Jul 11, 2005 6:56:50 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
New Firefox 1.0.5 - 12 July 2005

The new Firefox 1.0.5 has been released with security updates at http://www.mozilla.org/products/firefox/
[Jul 13, 2005 2:31:44 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: New Firefox 1.0.6 - 19 July 2005

The new Firefox 1.0.6 has been released at http://www.mozilla.org/products/firefox/

This is NOT a security update. Therefore I have not bothered to download it. There is an article about it in The Register: http://www.theregister.com/2005/07/21/moz_stability_update/

Firefox update fixes stability glitches
By John Leyden
Published Thursday 21st July 2005 12:52 GMT

The Mozilla Foundation rushed out a new version of Firefox on Tuesday to address stability problems introduced when it fixed a series of security vulnerabilities last week. Firefox Version 1.0.6 restore API compatibility for extensions and web applications that did not work in Firefox 1.0.5, a release itself designed to fix a variety of security vulnerabilities collectively rated as critical.

In a related move, Thunderbird 1.0.6 is now available for download. This latest version of the Mozilla Foundation's email client is designed to resolve extension problems that were accidentally introduced in Thunderbird 1.0.5. In particular, the popular Enigmail PGP add-on should now work correctly.

Credit the Mozilla Foundation for releasing stable versions quickly after discovering glitches but the need for further updates does illustrate the software reliability problems over security updates exist outside Redmond. ®
[Jul 21, 2005 1:51:47 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: New Mozilla Suite 1.7.10 - 21 July 2005

The new Mozilla Suite has been released at http://www.mozilla.org/products/mozilla1.x/

This is the first new release since May. It is the equivalent of Firefox 1.0.6 and has all the security updates.
[Jul 22, 2005 4:11:31 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: New Mozilla Suite 1.7.11 - 01 Aug 2005

The new Mozilla Suite has been released at http://www.mozilla.org/products/mozilla1.x/
There are some email changes.
[Aug 2, 2005 10:48:47 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Re: New Mozilla Suite 1.7.11 - 01 Aug 2005

The new Mozilla Suite has been released at http://www.mozilla.org/products/mozilla1.x/
There are some email changes.

Thank You mycroft i havent been there for awhile--i have also been using the free Opera its pretty good but kinda complicated for a real old house painter like me
[Aug 2, 2005 2:48:40 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
12 Sep 2005 Mozilla Workaround: Disabling International Domain Names

Here is the official bulletin on how to disable some buggy code in Firefox and Mozilla Suite until iy can be patched to work correctly: https://addons.mozilla.org/messages/307259.html
[Sep 13, 2005 1:27:13 AM]   Link   Report threatening or abusive post: please login first  Go to top 
Former Member
Cruncher
Joined: May 22, 2018
Post Count: 0
Status: Offline
Reply to this Post  Reply with Quote 
Firefox 1.0.7 - 21 Sep 2005

The new Firefox 1.0.7 can be downloaded from http://www.mozilla.org/products/firefox/
Quoting from MozillaZine at http://www.mozillazine.org/
Mozilla Firefox 1.0.7, a security and stability update to the flagship Mozilla browser, is now available for download. Fixes are included for the international domain name (IDN) link buffer overflow vulnerability and the Linux command line URL parsing flaw. There are also other security and stability changes, including a fix for a crash experienced when using certain Proxy Auto-Config scripts. In addition, some regressions introduced by previous 1.0.x security updates have been resolved.


If you followed the suggestion to disable IDN on Firefox 1.0.6
Type about:config into the address field and hit Enter.
In the Filter toolbar, type network.enableIDN
Right click on the the network.enableIDN item and select toggle to change value to false.
then you will have to reenable IDN manually by toggling network.enableIDN back to TRUE. The config settings on your browser are not changed by updates, so any time you change a setting to provide temporary protection from a security bug, you have to change it back once the bug is fixed.
[Sep 21, 2005 3:22:48 PM]   Link   Report threatening or abusive post: please login first  Go to top 
Posts: 30   Pages: 3   [ Previous Page | 1 2 3 ]
[ Jump to Last Post ]
Post new Thread