Mozilla Firefox 1.5.0.2


Recommended Posts

This was great. I got a message box informing me of the already installed update and to restart Firefox. These guy (and gals) have come a long way to make the best browser on the market (IMHO). MS might as well buy Mozilla 'cause that's the only way they'll have a decent browser.

Firefox 1.5.0.2 Fixes 21 Vulnerabilities

The Mozilla Foundation released an update to fix 21 security vulnerabilities in their Web browser, Firefox 1.5 for Windows, Linux, and Mac. If one of your users visits a malicious Web page, an attacker could exploit the worst of these vulnerabilities to execute code on that user's computer, with that user's privileges, possibly gaining complete control of the computer. If you use Firefox on any platform, you should download and deploy version 1.5.0.2 as soon as possible.

The Mozilla Foundation released Firefox 1.5.0.2, fixing 21 security vulnerabilities, as well as a few other stability issues, in the popular Web browser. Many of these vulnerabilities could allow a remote attacker to execute arbitrary code on your users' computers. We highlight three of the more worrisome flaws below:

An integer overflow in CSS Letter-Spacing. Firefox's CSS Letter-Spacing property suffers from an integer overflow vulnerability. By enticing one of your users to a malicious Web page, an attacker could exploit one of these integer overflows to execute code on that user's computer with the user's privileges. If you give your users local administrative privileges, an attacker could potentially exploit this flaw to gain control of their system.

Code execution vulnerability in particular JavaScript method. A flaw in a particular JavaScript method (called crypto.generateCRMFRequest) allows remote attackers to execute code on one of your user's machines with that user's privileges. However, like the flaw above, the attacker would first have to entice his victim to a malicious Web page for this attack to succeed.

Flaws in DHTML handling may allow code execution. Firefox suffers from several security vulnerabilities and crash bugs involving the way it handles DHTML Web content. Some of these vulnerabilities could allow attackers to execute code on your users' computers with their privileges. Like both flaws above, the hacker would have to entice your users to a malicious Web page in order to exploit these flaws.

These three flaws alone should convince you to update your Firefox users as soon as possible. However, if you'd like to know more about the remaining vulnerabilities, check out Firefox's known issues page.

Mozilla has updated Firefox to version 1.5.0.2 in order to correct these security vulnerabilities. If you use Firefox in your network, download and deploy version 1.5.02 as soon as possible.

Windows

Mac OS X

These attacks arrive as normal-looking HTTP traffic, which you need to allow through your firewall so your end users can access the World Wide Web. Therefore, the patches above are your best solution.

Thought that this may help anyone looking for help or downloads!

Firefox 1.5.0.2 Fixes 21 Vulnerabilities

It is Firefox 1.0.8 that has 21 or rather 18 Vulnerabilities fixed, NOT Firefox 1.5.0.2 as it only actually has 7 vulnerabilities fixed. http://www.mozilla.org/projects/security/k...rabilities.html

https://www.neowin.net/index.php?act=view&id=32838&cid=451400

Most of those advisories don't affect 1.5.0.1. The ones at the start say they affect Firefox before 1.5.0.2; the rest say they affect Firefox before 1.5 when in fact only 7 fixes are featured in 1.5.0.2 compared to a whopping 18 in 1.0.8.

By the way for Firefox 1.0.8 unlike what they planned in the past they decided that 1.0.8 will be the last of the old Aviary1.0.1 Branch releases unless something comes up to warrant a 1.0.9

Glad to say that it does fix a few of them.

  • Memory leaks
    • 321283 - Using Find causes documents to leak.
    • 323532 - Leak when using history autocomplete.
    • 323377 - Lots of leaks in nsInternetSearchService.

Yet it may have introduced a whole new BIGGER memory leak...

I've had to regress to 1.5.0.1 to avoid it crashing. The memory footpront is usually between 100MB and 250MB even with just 1 tab open! When it happens I can't even kill the process! I can't even shut down! Has to be a hard power off...

Just compliling some more evidence on another machine to submit a bug.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • LOL. Can't even quote and edit a comment correctly. Figures you're a Linux user.
    • I have disabled it, but the app is still taking space. I have a Mac and it is only possible to disable Ai on that, but I think that bit does get rid of the AI components after a while. What we are told is that we agree to all this when we use the devices as it is in the end user agreements, their software, they can do what they like. I doubt that any bill will happen in the U.S, the government there are in league with big tech firms. The E.U maybe, they seem to have some guts when it comes to tech companies. The U.K is not in the E.U, but some things still affect us. Our government is as gutless when it comes to tech companies as the U.s government.
    • WebChangeMonitor 26.06 by Razvan Serea Monitors allows you to quickly check a number of web pages and tracks changes based on the content of the web pages. Allows to monitor several protocols, including HTTP and HTTPS. Allows to view and record differences. Available for Win7/10, Linux and others. WebChangeMonitor features: Allows monitoring of web pages and informs about content changes Indication of states of currently monitored items in the tool and taskbar Reporting as sound and/or email as well as log file or HTML log Several configuration / filter options Support all protocols, e.g. http, https Multi-threaded, running in the background Bulk-import and bulk-export of items (from/to CSV) to monitor Export of results to CSV file for further processing Allows running command on items states and/or showing diff (changes) of content with preferred diff-tool ...and many more! Open Source (C++, wxWidgets) Cross platform for Windows (7/10), Linux, RPi and Mac (if self-compiled) WebChangeMonitor 26.06 release notes: Release 26.06 brings mostly s but updates the underlying core infrastructure. A major compiler is used for both x86/x64 and WoA64 architectures. This also means that all core libraries are re-compiled accordingly which required some changes in the build scripts. One of the core libraries (cURL) has been updated to address vulnerabilities and a nasty linker error that was causing the need for a dedicated patch which could now be eliminated. Download: WebChangeMonitor 64-bit | Setup 64-bit | ~10.0 MB (Open Source) Download: WebChangeMonitor 32-bit | Setup 32-bit View: WebChangeMonitor Website | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Dedicated
      Mark Spruce earned a badge
      Dedicated
    • Collaborator
      conkir earned a badge
      Collaborator
    • Rising Star
      olavinto went up a rank
      Rising Star
    • One Month Later
      lamborghiniv10 earned a badge
      One Month Later
    • Week One Done
      lamborghiniv10 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      482
    2. 2
      PsYcHoKiLLa
      257
    3. 3
      Steven P.
      74
    4. 4
      +Edouard
      69
    5. 5
      Skyfrog
      68
  • Tell a friend

    Love Neowin? Tell a friend!