Critical Flaws found in Firefox & Thunderbird


Recommended Posts

The Mozilla Project has issued a warning for a series of "highly critical" security holes in three of its core projects, including its flagship Firefox Web browser and the Thunderbird e-mail client.

See this article for details:

http://www.internetnews.com/dev-news/article.php/3408301

I noticed that.... :unsure:

If the bugs reported in the article above are relating to the announcement on Mozilla.org's security page, in this press release, then any current PreRelease download should have it. Although it is not very clear. I would think that they would make it 1.0aPR or 1.0-1PR or some other designation to show that is includes the fixes which are apparently already released.

Anyone else have insight into this?

An advisory released by Secunia warned that the flaws carry a "highly critical" rating and affects all versions of the software prior to Mozilla 1.7.3, Firefox 1.0PR and Thunderbird 0.8.

That means that current versions of the software are clean. Or at least that's what it looks like to me

I found out more on this...

The bug fixes accompany the release of the Firefox 1.0 preview release (PR), a nearly-finished version of the project's next-generation browser.
http://www.infoworld.com/article/04/09/15/...llaflaws_1.html

and

The holes affect versions prior to Mozilla 1.7.3, Firefox 1.0PR, and Thunderbird 0.8.
http://www.theinquirer.net/?article=18460

So, it seems that .9x is safe, as is 1.0PR

Looks like the first article was a bit sensationalist. These were likely bugs in their daily builds, but not in the released versions....

I am still using 0.9.3 - should I now get the latest 1.0PR or is there a 0.9.4 out with this patch?  I couldn't see any advice on the mozilla.org site

Yeah im wondering the same! :blink:

Edit: Yeh sorry I cant read silly me :angry:

Thanks for the info mark.

For those of you running Firefox ...

Check out the WinTel optimized builds for specific CPU instruction sets...

http://www.moox.ws/tech/mozilla/

They are TREMENDOUSLY faster than the builds released by Mozilla

Per Moox's website:

Optimized Firefox & Thunderbird Builds

I build optimized builds of both the Firefox browser and the Thunderbird email client. My builds are designed for maximum speed and stability and I use both the BRANCH/AVIARY and TRUNK source trees. For the uninitiated, BRANCH builds are more stable than TRUNK builds, which are made from the absolute bleeding edge of the source code. For a complete description of the differences, please see this thread at Mozillazine. I also make milestone and release builds, as well as custom builds upon email request. Occasionally I will also do Firefox builds with SVG enabled. Additional information on SVG can be found at Mozilla and Croczilla.

I am currently releaseing three versions, or "M" builds - M1, M2, and M3. Each M version is designed for compatibility wirh particular processors and/or instruction sets.

Official thread on mozillaZine:

http://forums.mozillazine.org/viewtopic.php?t=75503

:yes:

For those of you running Firefox ...

Check out the WinTel optimized builds for specific CPU instruction sets...

http://www.moox.ws/tech/mozilla/

They are TREMENDOUSLY faster than the builds released by Mozilla

Yep, or better still use bangbang's one.

https://www.neowin.net/forum/index.php?showtopic=191297

You will need a processor that supports SSE2 though.

On topic: It seems like they announced the bug after it had been fixed. If this is so, I think that's a very good idea.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Tor Browser 15.0.15 by Razvan Serea Protect your privacy. Defend yourself against network surveillance and traffic analysis. Tor is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet. The Tor software protects you by bouncing your communications around a distributed network of relays run by volunteers all around the world: it prevents somebody from watching your Internet connection and learning what sites you visit, it prevents the sites you visit from learning your physical location, and it lets you access sites which are blocked. The Tor Browser Bundle lets you use Tor on Windows, Mac OS X, or Linux without needing to install any software. It can run off a USB flash drive, comes with a pre-configured web browser to protect your anonymity, and is self-contained. Tor Browser 15.0.15 changelog: All Platforms Updated NoScript to 13.6.20.1984 Updated Tor to 0.4.9.9 Bug tor-browser#42436: Allow for multiple configured (front, reflector) domain fronting pairs in Moat module Windows + macOS + Linux Bug tor-browser#44997: Captcha doesn't work in TB desktop Linux Bug tor-browser#44886: Backport tor-browser#44361: Notify Linux i686 users that they won't receive updates anymore Download: Tor Browser (64-bit) | Tor Browser (32-bit) | 109.0 MB (Open Source) View: Tor Browser Website | Other Operating Systems Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Less disk space means less bandwidth demands which means lower operating costs for service providers... that's where money talks. ... cuz it's not about improving video quality!... that's just marketing spin.
    • And thereby lies the rub. AV1 support is not as wide as paid analysts would have the industry believe. With AV2 around the corner, it's going cause more time backlog in adoption (how many recent purchasers will upgrade yet-again within the next 6-12 months? most would rather stay pat for another 1+ years before even thinking about upgrading their setups).
    • Microsoft OneDrive is getting a simple yet much needed feature by Sayan Sen Microsoft has been steadily expanding OneDrive’s file management capabilities over the years, including for shared content and shortcuts, although it has had its flaws, too. The cloud storage platform introduced support for folder shortcuts several years ago, allowing users to pin frequently accessed shared folders from OneDrive, SharePoint, and Teams. Now, Microsoft is refining that experience further with a new way to organize those shortcuts as revealed in a recent Microsoft 365 roadmap addition. Previously, shortcuts added through the “Add shortcut to My files” option would appear alongside all other files and folders in the root of a user's OneDrive. And although it's meant to be useful, this approach could also create clutter along the way, especially for heavy users who may have to work with large numbers of shared folders across multiple projects and teams on their systems. This is where Microsoft’s latest feature comes in, as it is looking to address this inconvenience by giving users the option to place new shortcuts inside a dedicated “Shortcuts” folder instead. The feature is designed to keep shortcut links organized into a single location instead of scattering throughout the main OneDrive directory. Hence, the idea is to make navigation and usability easier and simpler. The first time a user chooses this option, OneDrive will automatically create the folder, and to help make it stand out from the other folders, the Shortcuts folder will have a distinct visual identity featuring a unique color and a building-style icon. That being said, the new Shortcuts will behave just like any other folder in OneDrive, and as such, users will be able to move it to a different location, rename it, share it with others, or remove it entirely if they prefer a different structure. You can view the entry on the Microsoft 365 roadmap website here. Currently, the feature is in the "in development" phase, but the tech giant expects the rollout to start next month (July 2026). Do keep in mind, though, that new feature rollouts often get delayed.
  • Recent Achievements

    • One Month Later
      B2Proxy earned a badge
      One Month Later
    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
    • Week One Done
      oliviaexpo earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      482
    2. 2
      PsYcHoKiLLa
      227
    3. 3
      Skyfrog
      71
    4. 4
      FloatingFatMan
      60
    5. 5
      Nick H.
      54
  • Tell a friend

    Love Neowin? Tell a friend!