1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

Security problem found and patched in Firefox

Discussion in 'BBS Hangout' started by Vengeance, Jul 8, 2004.

Tags:
  1. Vengeance

    Vengeance Member

    Joined:
    Nov 29, 2000
    Messages:
    5,894
    Likes Received:
    23
    There is a patch for it:

    Go here:
    http://update.mozilla.org/extensions/moreinfo.php?id=154
    for the fix, and then restart Firefox.

    Also, you could <a href="http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/0.9.2/FirefoxSetup-0.9.2.exe">download 0.9.2</a> to get the fix.

    It's potentially significant, but it'd be pretty hard to exploit, and there are no known exploits in the wild. Only affects 2k and XP users.

    <a href="http://bugzilla.mozilla.org/show_bug.cgi?id=167475">Here's the bug location</a> in Bugzilla.

    <a href="http://bugzilla.mozilla.org/show_bug.cgi?id=250180">Or here</a>

    <a href="http://www.eweek.com/article2/0,1759,1621463,00.asp">Article about it</a>.

    Now this is the thing, it's not so much of a bug with Mozilla or Firefox, but rather a "vulnerability" with the way that Firefox works with Windows. Mozilla/Firefox passes any URIs it doesn't know to Windows and Windows automatically executes them. If Windows didn't automatically execute them (which a more secure OS wouldn't), it wouldn't be a problem. But, if Firefox didn't let Windows execute them with the browser's permissions (rather, force it to lower permissions), it'd be fixed too. So when it comes down to it, it's really kind of a shared problem, but it's certainly a problem that should be patched.

    <i>edit</i>: Also, it's a problem that would be fixed by Windows in SP2.

    Don't let that send you back to IE, or stop you from making the switch though. Firefox is still the best browser out there!
     
    #1 Vengeance, Jul 8, 2004
    Last edited: Jul 8, 2004
  2. Lil Pun

    Lil Pun Member

    Joined:
    Oct 6, 1999
    Messages:
    34,143
    Likes Received:
    1,038
    I licked on it but how can you tell if it is installed?
     
  3. Vengeance

    Vengeance Member

    Joined:
    Nov 29, 2000
    Messages:
    5,894
    Likes Received:
    23
    restart the browser, then if you go to the address bar and type:

    shell:.mp3 and it starts your MP3 program, it's not fixed.
     
  4. Lil Pun

    Lil Pun Member

    Joined:
    Oct 6, 1999
    Messages:
    34,143
    Likes Received:
    1,038
    OK it started WMP, what did I do wrong?
     
  5. AroundTheWorld

    Joined:
    Feb 3, 2000
    Messages:
    83,288
    Likes Received:
    62,281
    :confused: :D
     
  6. Vengeance

    Vengeance Member

    Joined:
    Nov 29, 2000
    Messages:
    5,894
    Likes Received:
    23
    you installed the extension, then restarted the browser, right? All Firefox windows were closed, including Download manager?

    If so, I'd try rebooting 1st, and if that doesn't do it (and another patch install doesn't), then I'd d/l and install 0.9.2.
     
  7. AroundTheWorld

    Joined:
    Feb 3, 2000
    Messages:
    83,288
    Likes Received:
    62,281
    Tabbed browsing is cool

    IE has its flaws.

    But - so do all the Mozilla versions. They have problems with some pages that use javascript. Whether this is caused by some proprietary javascript standards designed for IE is a different question, because they should be able to emulate that.

    With regards to security questions, I think one of the main reasons that there are less security problems in Mozilla/Firefox is mainly that there are much less users, so it is less attractive to find and exploit security issues.
     
  8. KaiSeR SoZe

    KaiSeR SoZe Member

    Joined:
    Mar 23, 2003
    Messages:
    8,395
    Likes Received:
    39
    I love open source :D
     
  9. Lil Pun

    Lil Pun Member

    Joined:
    Oct 6, 1999
    Messages:
    34,143
    Likes Received:
    1,038
    DOH!!!
     
  10. Lil Pun

    Lil Pun Member

    Joined:
    Oct 6, 1999
    Messages:
    34,143
    Likes Received:
    1,038
    I got it, thanks and keep me/us updated on all new patches and fixes that come out for FF. :)
     
  11. daNasty

    daNasty Member

    Joined:
    Nov 1, 2003
    Messages:
    701
    Likes Received:
    0
    God, I really hated this internet nowaday. I mean it's getting worse and worse! I'm getting sick and tired of having to clean and go through idiotic step to keep my compter clean almost constantly. Especially those hijack **** which totally p!sses me off. There should be a law against this spam crap.

    Its not even safe to surf p*rn anymore. :( :mad: :eek:
     
  12. KaiSeR SoZe

    KaiSeR SoZe Member

    Joined:
    Mar 23, 2003
    Messages:
    8,395
    Likes Received:
    39
    thanks for the heads up
     
  13. KingCheetah

    KingCheetah Atomic Playboy
    Supporting Member

    Joined:
    Jun 3, 2002
    Messages:
    59,079
    Likes Received:
    52,748
    I never have these kinds of problems with my MS IE.
     
  14. Behad

    Behad Member

    Joined:
    Feb 20, 1999
    Messages:
    12,358
    Likes Received:
    193
    I did this and it went to shell.com. I guess I did it right?

    [​IMG]
     
  15. SmeggySmeg

    SmeggySmeg Member

    Joined:
    Feb 23, 1999
    Messages:
    14,887
    Likes Received:
    123
    nice work smartass

    btw pics on the way in a few minutes
     
  16. Behad

    Behad Member

    Joined:
    Feb 20, 1999
    Messages:
    12,358
    Likes Received:
    193
    I wasn't joking! I'm serious, it took me to shell.com. I was like WTF???


    Send them to my home addy


    Edit: Cool, I finally made someone's signature!
     
  17. KaiSeR SoZe

    KaiSeR SoZe Member

    Joined:
    Mar 23, 2003
    Messages:
    8,395
    Likes Received:
    39
    i go to shell.com also
     
  18. mrpaige

    mrpaige Member

    Joined:
    Feb 5, 2000
    Messages:
    8,831
    Likes Received:
    15
    Same for me with the Shell.com.
     
  19. macalu

    macalu Member

    Joined:
    May 19, 2002
    Messages:
    16,942
    Likes Received:
    836
    ditto

    it didn't open winamp so does that mean i got it installed?
     
  20. Lil Pun

    Lil Pun Member

    Joined:
    Oct 6, 1999
    Messages:
    34,143
    Likes Received:
    1,038
    Yes, or so I'm told.
     

Share This Page