main
Report a problem

Mozilla postpones Firefox 2 fix

Steven Parker   on 21 February 2007 - 10:07 · 5 comments & 3000 views

Advertisement (Why?)
Mozilla will delay the next security update for Firefox so it can test a fix for a flaw that could be used by attackers by skirt security restrictions.

The flaw, disclosed by Polish researcher Michal Zalewski on the Full Disclosure security mailing list, could let a malicious site manipulate the authentication cookies for other sites' pages. It is present in the most recent version of the open-source browser, 2.0.0.1.

According to Zalewski, the bug might allow hackers to "tamper with the way these [third-party] sites are displayed or how they work."

Mozilla developers jumped on the bug and produced a fix by the next day. However, adding the patch to the Firefox 2.0.0.2 and 1.5.0.10 updates, which are still under development, will require more work. "We had to respin for [the patch] and now have Firefox 2.0.0.2 rc4 and 1.5.0.10 rc2 builds," wrote Firefox developer Jay Patel on the Mozilla.dev.planning forum. "We are [now] shooting for a target ship date of Thursday 2/22."

View: Full Article @ PC Advisor

Post a comment · Send to friend Comments · There are 5 additional comments
#1 Cryton on 21 Feb 2007 - 12:03
The target date for Firefox 2.0.0.2 is now Tue 27th Feb, and there's an RC5 out.
Changelog: http://forums.mozillazine.org/viewtopic.php?t=518120
(3 replies) #2 ThaCrip on 21 Feb 2007 - 15:58
well atleast it's getting fixed properly ... cause i would rather wait a little longer for a quality patch then have em half a*s it and then release v2.0.0.3 a week or two later.
#2.1 vetbangbang023 on 21 Feb 2007 - 21:38
What amuses me is that if this were MS and IE, people would be flipping out saying how much more quickly Mozilla could get a patch out. I don't mind the wait (I use the trunk, anyway), but people tend to be accepting of things solely based on the company involved.
#2.2 +mrbester on 22 Feb 2007 - 10:27
Quote - (bangbang023 said @ #2.1)
What amuses me is that if this were MS and IE, people would be flipping out saying how much more quickly Mozilla could get a patch out.

Disingenuous. Mozilla are getting a patch out much more quickly than Microsoft would. Not only that, they're also being transparent about it by saying "we have a patch, but we need to fully test it and add it into the next update". Better that they put it in the next update rather than having to release again in a couple of days.

In any case 2/22 is today. The story was posted yesterday. Not quick enough for you?
#2.3 +Dakkaroth on 22 Feb 2007 - 19:08
^ Seriously. With Microsoft, you'll be waiting a month. I mean, don't get me wrong, I like getting free updates; I just don't like the fact that one of the windows in my house has to remain open for a month before someone gets up and closes it.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)