Mozilla Firefox 1.5.0.2


Recommended Posts

This was great. I got a message box informing me of the already installed update and to restart Firefox. These guy (and gals) have come a long way to make the best browser on the market (IMHO). MS might as well buy Mozilla 'cause that's the only way they'll have a decent browser.

Firefox 1.5.0.2 Fixes 21 Vulnerabilities

The Mozilla Foundation released an update to fix 21 security vulnerabilities in their Web browser, Firefox 1.5 for Windows, Linux, and Mac. If one of your users visits a malicious Web page, an attacker could exploit the worst of these vulnerabilities to execute code on that user's computer, with that user's privileges, possibly gaining complete control of the computer. If you use Firefox on any platform, you should download and deploy version 1.5.0.2 as soon as possible.

The Mozilla Foundation released Firefox 1.5.0.2, fixing 21 security vulnerabilities, as well as a few other stability issues, in the popular Web browser. Many of these vulnerabilities could allow a remote attacker to execute arbitrary code on your users' computers. We highlight three of the more worrisome flaws below:

An integer overflow in CSS Letter-Spacing. Firefox's CSS Letter-Spacing property suffers from an integer overflow vulnerability. By enticing one of your users to a malicious Web page, an attacker could exploit one of these integer overflows to execute code on that user's computer with the user's privileges. If you give your users local administrative privileges, an attacker could potentially exploit this flaw to gain control of their system.

Code execution vulnerability in particular JavaScript method. A flaw in a particular JavaScript method (called crypto.generateCRMFRequest) allows remote attackers to execute code on one of your user's machines with that user's privileges. However, like the flaw above, the attacker would first have to entice his victim to a malicious Web page for this attack to succeed.

Flaws in DHTML handling may allow code execution. Firefox suffers from several security vulnerabilities and crash bugs involving the way it handles DHTML Web content. Some of these vulnerabilities could allow attackers to execute code on your users' computers with their privileges. Like both flaws above, the hacker would have to entice your users to a malicious Web page in order to exploit these flaws.

These three flaws alone should convince you to update your Firefox users as soon as possible. However, if you'd like to know more about the remaining vulnerabilities, check out Firefox's known issues page.

Mozilla has updated Firefox to version 1.5.0.2 in order to correct these security vulnerabilities. If you use Firefox in your network, download and deploy version 1.5.02 as soon as possible.

Windows

Mac OS X

These attacks arrive as normal-looking HTTP traffic, which you need to allow through your firewall so your end users can access the World Wide Web. Therefore, the patches above are your best solution.

Thought that this may help anyone looking for help or downloads!

Firefox 1.5.0.2 Fixes 21 Vulnerabilities

It is Firefox 1.0.8 that has 21 or rather 18 Vulnerabilities fixed, NOT Firefox 1.5.0.2 as it only actually has 7 vulnerabilities fixed. http://www.mozilla.org/projects/security/k...rabilities.html

https://www.neowin.net/index.php?act=view&id=32838&cid=451400

Most of those advisories don't affect 1.5.0.1. The ones at the start say they affect Firefox before 1.5.0.2; the rest say they affect Firefox before 1.5 when in fact only 7 fixes are featured in 1.5.0.2 compared to a whopping 18 in 1.0.8.

By the way for Firefox 1.0.8 unlike what they planned in the past they decided that 1.0.8 will be the last of the old Aviary1.0.1 Branch releases unless something comes up to warrant a 1.0.9

Glad to say that it does fix a few of them.

  • Memory leaks
    • 321283 - Using Find causes documents to leak.
    • 323532 - Leak when using history autocomplete.
    • 323377 - Lots of leaks in nsInternetSearchService.

Yet it may have introduced a whole new BIGGER memory leak...

I've had to regress to 1.5.0.1 to avoid it crashing. The memory footpront is usually between 100MB and 250MB even with just 1 tab open! When it happens I can't even kill the process! I can't even shut down! Has to be a hard power off...

Just compliling some more evidence on another machine to submit a bug.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The useful lapdogs  
    • Nobody is buying a PS5 only for playing Until Dawn 2. Their loss.
    • If you actually used it instead of responding like a petulant child you might be surprised. I switched from Google some time ago and have been very satisfied.
    • I am one of the first people to use the DXVK technology. In the channel below you can see some videos that I have made using this technology, including Assassin's Creed Odyssey. https://www.youtube.com/@nahum7995/videos Assassin's Creed Odyssey experienced several bugs and technical issues during its first months after release. It launched with its own fair share of funny but frustrating glitches. I ran it on DXVK 9 days after its release and I played it for many hours but didn't see a single significant bug on Linux. Assassin's Creed Odyssey is widely celebrated for pushing the franchise in bold new directions and specifically for nailing several elements better than any other title in the AC series: Player Choice & Branching Narrative, The Mercenary & Cultist System, Mythological Integration, Overpowered Combat Abilities, Open World Exploration But what I'm trying to point out is that this game wasn't quite playable on most windows systems, until a few months after its release when most of the bugs were fixed. However, on Linux it ran completely flawless from day one, although DXVK had seen little development and refinement at the time. What do you think the situation will be in 2026 now that most bugs and glitches of DXVK have been completely eliminated? This is information from Google about these situations that I am quoting. In many cases, using DXVK (a translation layer that converts DirectX 9, 10, or 11 into Vulkan) can result in more stable frame times and higher performance than native Windows rendering. This happens primarily by bypassing driver overhead and multithreading draw calls that were previously restricted to a single CPU core. Older APIs (like DirectX 9 and 11) are largely single-threaded on the CPU side. DXVK translates these calls to Vulkan, which is highly multi-threaded. This reduces CPU-bound stuttering on weaker processors. In certain cases, GPU manufacturers (especially AMD) have significantly better and more modern Vulkan drivers than they do for legacy DirectX. Vulkan gives developers—and in this case, the translation layer—closer control over how resources are held in VRAM. This can prevent micro-stutters and sudden frame drops during chaotic gameplay. Yes, certain games, particularly older DirectX 9 to 11 titles, can run with fewer crashes on DXVK than on native Windows. By intercepting DirectX draw calls and translating them into the modern, highly efficient Vulkan API, DXVK bypasses the limitations and poor driver support that cause instability in aging game engines. PlayStation 1, PlayStation 2 and PlayStation 3 can be easily and perfectly emulated on Linux. In fact, modern Linux emulators offer high-performance upscaling, widescreen patches, and automatic controller mapping out of the box.                                                                                                                                                                                                                                                                                                                                 PlayStation 1/2/3 games look drastically better on Linux thanks to resolution upscaling. Furthermore, it is also a fact that you cannot play many fun games on Windows either, isn't it? - The Nintendo Switch has an extensive library of exclusive games. - PlayStation has an extensive library of exclusive games - Android has "mobile-exclusive" games, meaning they are exclusive to mobile devices (iOS and Android) and aren't available on PC or consoles. And finally, it is also the case that in the next five years there will be games that millions of people will say you absolutely must play and that they want to play this specific game that released a few days ago. However, the other side of this story is that currently, absolutely no one cares that they cannot play these upcoming games right now.
  • Recent Achievements

    • One Month Later
      nothanks earned a badge
      One Month Later
    • One Month Later
      B2Proxy earned a badge
      One Month Later
    • One Year In
      MadMung0 earned a badge
      One Year In
    • Week One Done
      jefred earned a badge
      Week One Done
    • Apprentice
      JoeyNeo went up a rank
      Apprentice
  • Popular Contributors

    1. 1
      +primortal
      486
    2. 2
      PsYcHoKiLLa
      232
    3. 3
      Skyfrog
      79
    4. 4
      FloatingFatMan
      68
    5. 5
      Michael Scrip
      58
  • Tell a friend

    Love Neowin? Tell a friend!