View Full Version : Critical flaws found in firefox


Emma S
05-13-05, 08:11 PM
Critical flaws were found in the Firefox browser a few days ago,I noticed there isn't any information about it here,so here it is for anyone who has missed it so far:
http://news.bbc.co.uk/1/hi/technology/4541641.stm


http://www.mozilla.org/products/firefox/
^Download the latest firefox,which has been patched.

Ichpuchtli
05-13-05, 09:37 PM
I am useing firefox right now and nothing is wrong with it. It works just fine. And what does this exactly mean, with all these flaws could you put them into clearer English for me.

Imnapl
05-13-05, 10:57 PM
This information is from the link that Emma S kindly provided.

"Although the vulnerabilities, reported on Saturday, had been identified no cases had been reported of them being exploited.

Secunia said they were "extremely critical" because they could have let cookie and history information be used to get access to personal information or access previously visited sites.

The first flaw reported fooled the browser into thinking software was being installed by a legitimate, or safe, website.

The second was related to the software installation trigger which was not able to properly check icon web addresses which contain JavaScript code.

Potentially, a hacker could have taken advantage of the security flaws to secretly launch malicious code or programs."

exeter
05-14-05, 01:09 AM
In English, it means download firefox 1.04.

johny
05-14-05, 01:50 AM
Thanks, and another topic about the firefox extensions would be nice.

Ichpuchtli
05-14-05, 02:01 AM
Thanks I now understand what it is all about. I now know it doesn't affect me because I am using an older version maybe i should update.

Emma S
05-14-05, 11:13 AM
Thanks I now understand what it is all about. I now know it doesn't affect me because I am using an older version maybe i should update.
Yeah,the update would be worth it,if your using beta firefox/pre v1.0,it will have more bugs,and more vulnerabilities including the latest critical flaws.
I doubt it will really get taken advantage of but Firefox has become rapidly popular,
I've seen it get writeups in tabloid newspapers,and the more popular it gets,the more chance people will be looking for code exploits.
It's still better than using IE though.

I use both linux and windows beta firefox,and really need to upgrade them both to.
There's a bug in my linux version,crashes everytime I click on the google bar.


And,Micro$oft is apparently releasing IE7 in the summer; earlier than expected,I wonder if the popularity of firefox had anything to do with this!! :cool: :D

Ichpuchtli
05-14-05, 07:18 PM
Yea I use Linux. Well not all the times. I have six computers you see I like to fiddle with them 5 are working all of them have linux but 2 also have windows. I think 2 of em have the better linux and better firefox.

Emma S
05-14-05, 09:00 PM
Yea I use Linux. Well not all the times. I have six computers you see I like to fiddle with them 5 are working all of them have linux but 2 also have windows. I think 2 of em have the better linux and better firefox.
Fine choice of OS kernel you got there,Ichpuchtli,should have guessed from your tux av. though. :cool: :D


Better to be overly paranoid than to be oblivious to the possibilities I think-pity upgrading is so tedious. :(

Ichpuchtli
05-14-05, 09:17 PM
Yea.
I found a better tux Av but now I can't change it. I will soometime today get round to it I mean it is only 11:20 AM.

exeter
05-15-05, 12:28 AM
With something like gentoo's portage or *BSD's ports system, upgrading is a simple matter of "emerge -uD world" or "make world". :D