main

Mozilla issues fixes for Firefox, SeaMonkey Flaws

Amano   on 07 March 2007 - 14:06 · 12 comments & 4808 views

Advertisement (Why?)
The Mozilla Foundation has published a fix for a "critical" JavaScript vulnerability in the Firefox browser and the SeaMonkey application suite. The fix, released Monday, targets Firefox versions 2.0.0.2 and 1.5.0.10, as well as SeaMonkey versions 1.1.1 and 1.0.8. An earlier fix for a JavaScript problem allowed scripts from Web content to execute arbitrary code, the Mozilla Foundation said in a security update.

The vulnerability allowed uniform resource identifiers, or URIs, in image tags to be executed even if JavaScript was disabled in the program preferences, Mozilla said. Disabling JavaScript does not protect against the flaw, so the foundation recommended that users upgrade the applications to new versions. Mozilla's Thunderbird e-mail client was not affected by the vulnerability, it said.

News source: PC World

Post a comment · Send to friend Comments · There are 12 additional comments
(5 replies) #1 Cryton on 07 Mar 2007 - 14:21
Firefox 2.0.0.2 and 1.5.0.10 were releaed on Friday 23rd Feb 2007, not Monday [5th March]. However, Seamonkey 1.1.1 and 1.0.8 were released on Friday 2nd March 2007 (not Monday [5th March]) which is a bit closer.
#1.1 Davebo on 07 Mar 2007 - 14:25
**** this

Last edited by Davebo on 07 Mar 2007 - 14:38
#1.2 vetSlimy on 07 Mar 2007 - 14:29
Where does it say those versions were released Monday? Oh right, it doesn't.
#1.3 Cryton on 07 Mar 2007 - 15:24
Quote - (Slimy said @ #1.2)
Where does it say those versions were released Monday? Oh right, it doesn't.

Quote -
The fix, released Monday, targets Firefox versions 2.0.0.2 and 1.5.0.10

Did you even read the article?
#1.4 dev on 07 Mar 2007 - 15:37
Quote - (Cryton said @ #1.3)
Quote - (Slimy said @ #1.2)
Where does it say those versions were released Monday? Oh right, it doesn't.

Quote -
The fix, released Monday, targets Firefox versions 2.0.0.2 and 1.5.0.10

Did you even read the article?


nice of you to prove yourself wrong, the fix was released monday, not the firefox/seamonkey versions
#1.5 Cryton on 07 Mar 2007 - 15:42
Quote - (dev said @ #1.4)
nice of you to prove yourself wrong, the fix was released monday, not the firefox/seamonkey versions

So, um, a fix was release Monday, nearly two weeks after 2.0.0.2 was released? Evidently there's something I don't understand, so if anyone can clear it up that'd be great.

edit: The article is basically bullplop and the author very confused. The
Quote -
An earlier fix for a JavaScript problem allowed scripts from Web content to execute arbitrary code, the Mozilla Foundation said in a security update.

The vulnerability allowed uniform resource identifiers, or URIs, in image tags to be executed even if JavaScript was disabled in the program preferences, Mozilla said.
is referring to Mozilla Foundation Security Advisory 2006-72 (which was fixed in Fx 2.0.0.1, Fx 1.5.0.9 & SM 1.0,7).

This fix caused a regression:
  • #368655 [Core: DOM]-[FIX]Easy DoS by <img src="java script:for(;; );"> even if javascript disabled [All]
which is a DOS issue, and was fixed in Fx 2.0.0.2, Fx 1.5.0.10, SM 1.0.8 and 1.1.1. None of which were released on Monday.

Last edited by Cryton on 07 Mar 2007 - 16:13
(1 reply) #2 theblazingangel on 07 Mar 2007 - 14:51
i'm confused, are we supposed to be expecting firefox v2.0.0.3 or what?
#2.1 Cryton on 07 Mar 2007 - 15:26
Quote - (theblazingangel said @ #2)
i'm confused, are we supposed to be expecting firefox v2.0.0.3 or what?

A quick 2.0.0.3 release is in the pipeline to fix some stupid regressions that 2.0.0.2 introduced.
#3 drygnfyre on 07 Mar 2007 - 16:10
A fairly quick update, but if it's in the name of security, then I don't mind.
#4 Amano on 07 Mar 2007 - 19:48
Guys, there is a source for this article
(1 reply) #5 WDGC on 07 Mar 2007 - 21:52
Is this the same issue? If so, Firefox 2.0.0.2 and 1.5.0.10 are affected; in fact they are the 'fixes'.
Quote -
The security flaws were discovered in Firefox 1.5.0.9 and 2.0.0.1, as well as in SeaMonkey 1.0.7, according to a security advisory posted by Mozilla.

http://www.zdnet.com.au/news/software/soa/...39274063,00.htm
#5.1 WDGC on 07 Mar 2007 - 22:00
Firefox 2.0.0.2 and 1.5.0.10 are not affected; The lead article conveys an incorrect impression.

Quote -
The advisory shows the flaw was fixed in Firefox 2.0.0.2/1.5.0.10 and SeaMonkey 1.1.1/1.0

http://www.mozilla.org/security/announce/2...fsa2007-09.html

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)