main
Report a problem

Mozilla Security Update Fixes 7 Vulnerabilities

Slimy   on 24 February 2007 - 21:09 · 14 comments & 4452 views

Advertisement (Why?)
This week, Mozilla patched seven vulnerabilities with the latest security update, available both with automatic updates and manual download from the company's website, for Firefox 1.5.0.10 and Firefox 2.0.0.2. The security update was originally slated for a February 21 release but was pushed back to accommodate a fix for the location.hostname vulnerability. The vulnerability allows malicious Web sites to manipulate authentication cookies for third-party sites. "We strongly recommend that all Firefox users upgrade to this latest release. This update resolves the location.hostname vulnerability and other security and stability issues. Thanks to the work of our contributors, we have been able to address these issues quickly in order to minimize the security risk to Firefox users," said Mike Schroepfer, VP of engineering at Mozilla.

The open-source software maker is already working on another serious bug that Michal Zalewski, a Polish security researcher, described as a memory-corruption issue on his mailing list, Full Disclosure: "I noticed that Firefox is susceptible to a pretty nasty, and apparently easily exploitable memory corruption vulnerability. When a location transition occurs and the structure of a document is modified from within onUnload event handler, freed memory structures are left in inconsistent state, possibly leading to a remote compromise."

News source: InformationWeek

Post a comment · Send to friend Comments · There are 14 additional comments
(1 reply) #1 david13lt on 24 Feb 2007 - 21:34


Just noticed that it is updating... Hm..
#1.1 lardboy on 24 Feb 2007 - 22:12
That's weird I've updated to 2.0.0.2 twice now once last night and then I checked again after seeing this post and now I've apparently updated again
(3 replies) #2 Cryton on 24 Feb 2007 - 23:09
That memory corruption bug was fixed in 2.0.0.2 as well.
#2.1 franzon on 25 Feb 2007 - 09:21
NO, Mozilla fixed an old memory corruption flaw, but a new memory corruption flaw has been discovered and it's unpatched!
#2.2 Cryton on 25 Feb 2007 - 12:46
No! Read the article; at the end it says:
Quote -
Mozilla says it's working on that bug as well.

But click on the link to the bug, and you see it is RESOLVED FIXED for 1.8.0.10 and 1.8.1.2!! (Michal was testing against firefox 2.0.0.1, in which the bug was present, but it got fixed on the road to 2.0.0.2 by a different patch).

Last edited by Cryton on 25 Feb 2007 - 12:54
#2.3 RyanVM on 26 Feb 2007 - 01:22
Quote - (Cryton said @ #2.2)
No! Read the article; at the end it says:
Quote -
Mozilla says it's working on that bug as well.

But click on the link to the bug, and you see it is RESOLVED FIXED for 1.8.0.10 and 1.8.1.2!! (Michal was testing against firefox 2.0.0.1, in which the bug was present, but it got fixed on the road to 2.0.0.2 by a different patch).
While what you meant to say is correct, you didn't quite interpret the bug correctly. The RESOLVED FIXED refers to the patch that was checked in on the trunk (the future Fx3), not the 1.8 branches. If you read the comments near the bottom, you'll see that the bug just plain and simple doesn't affect 1.5.0.10/2.0.0.2 due to another fix which went in prior to it being released. They added the fixed1.8.0.10 & fixed1.8.1.2 keywords to reflect it being fixed in 1.5.0.10 & 2.0.0.2 so Joe Q. Public going to that bug will see that it doesn't affect those releases.

Last edited by RyanVM on 26 Feb 2007 - 01:28
(2 replies) #3 Buttus on 25 Feb 2007 - 01:36
nice! but it says my java console isn't compatible anymore... oh well...
#3.1 TRC on 25 Feb 2007 - 19:22
You may have an outdated version, mine works fine. Latest version is 5.0 Update 11.
#3.2 RyanVM on 26 Feb 2007 - 01:24
Quote - (TRC said @ #3.1)
You may have an outdated version, mine works fine. Latest version is 5.0 Update 11.
JRE 6.0 reports that error.
#4 drygnfyre on 25 Feb 2007 - 02:10
Thanks for the notice. I've updated all my Firefox sessions to 2.0.0.2.
(2 replies) #5 beardedwonder on 25 Feb 2007 - 02:54
So no IE fix yet? Won't the fanboys love this
#5.1 david13lt on 25 Feb 2007 - 08:22
As I remember IE 7 had several fixes already too...
#5.2 franzon on 25 Feb 2007 - 09:24
Quote - (david13lt said @ #5.1)
As I remember IE 7 had several fixes already too...


IE7 in Windows Vista is not affected
#6 em_te on 25 Feb 2007 - 16:03
The location.hostname bug was fixed and patched in less than 24 hours since it was reported.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)