PDA

View Full Version : Mozilla Security Flaw and Patch


Nino
7-9-04, 12:47 AM
Hi,
As for the browser, I use Mozilla Firefox and couldn't be happier. It is a stable browser with many good features which IE lacks, and is more secure. You can download it from http://www.mozilla.org/products/firefox/ :D

I use Mozilla too and I like it, but you can never be too sure when it comes to security:
Security hole found in Mozilla browser (http://news.com.com/Security+hole+found+in+Mozilla+browser/2100-1002_3-5262676.html?part=rss&tag=5262676&subj=news.1002.20)

Although, it's supposed to affect only Windows users.

extras
7-9-04, 01:42 AM
They have already a fix for that.
http://update.mozilla.org/extensions/moreinfo.php?id=154

Nino
7-9-04, 01:54 AM
They have already a fix for that.
http://update.mozilla.org/extensions/moreinfo.php?id=154

Yes, I know. The article tells me that.

extras
7-9-04, 02:00 AM
Yep. But that link was broken. ;)

(jj)
7-9-04, 04:43 AM
This Link (http://www.mozillazine.org/talkback.html?article=4960) works. :D

It also explains what the problem is and how to correct it until the next release comes out. There is also a link to a site where you can test your version for the vulnerability.

(jj)
7-9-04, 01:06 PM
**UPDATE**

The new "patched" versions of FireFox 0.9.2 and Thunderbird 0.7.2 have been released and can be downloaded at Mozilla.Org (http://www.mozilla.org/)

Nino
7-9-04, 02:43 PM
**UPDATE**

The new "patched" versions of FireFox 0.9.2 and Thunderbird 0.7.2 have been released and can be downloaded at Mozilla.Org (http://www.mozilla.org/)

It may be easier to just download the patch (http://update.mozilla.org/extensions/moreinfo.php?id=154) instead of the patched versions of the complete applications . . .
It's only 1 KB and can be downloaded and installed immediately.

XJnick
7-9-04, 11:52 PM
I use Mozilla too and I like it, but you can never be too sure when it comes to security:
Security hole found in Mozilla browser (http://news.com.com/Security+hole+found+in+Mozilla+browser/2100-1002_3-5262676.html?part=rss&tag=5262676&subj=news.1002.20)

Although, it's supposed to affect only Windows users.

Hi,

Yes, that's why I said "is more secure." Nothing is perfectly safe. Plus, I use Linux (and will NEVER use Windows on my computer again), so hopefully that gives me a safety advantage :p

Hmmm... I just downloaded 0.9 recently then 0.9.1 a few days later. Now I guess I'll go download 0.9.2. I do like having the most updated software :D

Bloodeye
7-10-04, 02:08 AM
It may be easier to just download the patch (http://update.mozilla.org/extensions/moreinfo.php?id=154) instead of the patched versions of the complete applications . . .
It's only 1 KB and can be downloaded and installed immediately.

OR...even easier yet would be to patch it yourself without the download.

http://www.mozillazine.org/
Firefox 0.9.2, Thunderbird 0.7.2, Mozilla 1.7.1 Coming Soon
"Alternatively, you can set the pref network.protocol-handler.external.shell in about:config to false to remove the exploit. (This will only set it on your current profile, if you have more than one profile, or could be creating more, you should use the XPI or the updated build.)"

Ahhh...the beauty of Mozilla/FireFox. The end-user can patch it without a big download. How big would IE's patch be?....maybe a gig or so. :D

(jj)
7-10-04, 03:12 AM
Actually, the only people who have to worry about this patch, are the ones running Windows (mostly Win XP).

Now who would have ever guessed that? :D