scuzzman Posted March 24, 2005 Report Share Posted March 24, 2005 The Mozilla Foundation issued a patch this week for a previously undisclosed hole in its popular Firefox Web browser and is encouraging Firefox users to download the software update as soon as possible. The nonprofit organization released Firefox 1.0.2 (available as a free download) to fix a buffer overflow vulnerability in a Firefox feature for processing GIF image files. The patch is the second security patch issued in less than a month, but the foundation reassured users that the browser's open source platform is secure, and says it does not know of any active exploits for the hole.The GIF processing hole was discovered by Internet Security Systems (ISS) and makes Firefox users who are running earlier versions of the browser vulnerable to buffer overflow attack, according to a statement released by the Mozilla Foundation.ISS discovered the hole in a review of the Firefox source code, which is available on the Internet.In a statement attributed to Chris Hofmann, the foundation's director of engineering, the discovery of the hole and release of a patch shortly after are evidence that the open source software model is safer and more secure than closed-source commercial code, because it is "scoured by thousands" of contributors, developers and professionals, and "not just the company's development team."Full story here. Quote Link to comment Share on other sites More sharing options...
andsome Posted March 24, 2005 Report Share Posted March 24, 2005 Just as I have said. As Firefox gets more popular, so attacks from the mindless will increase. I am sticking to IE. Quote Link to comment Share on other sites More sharing options...
scuzzman Posted March 24, 2005 Author Report Share Posted March 24, 2005 While that may be true, keep in mind this hole was never exploited before or after it was found. Not near as much can be said for IE, MS doesn't patch a hole until it's exploited. Quote Link to comment Share on other sites More sharing options...
andsome Posted March 24, 2005 Report Share Posted March 24, 2005 I just hope no hole of mine ever gets patched Quote Link to comment Share on other sites More sharing options...
Wilt Posted March 24, 2005 Report Share Posted March 24, 2005 Or exploted :unsure: :lol: Quote Link to comment Share on other sites More sharing options...
andsome Posted March 24, 2005 Report Share Posted March 24, 2005 Or exploted :unsure: :lol:If you mean exploited, heaven forbid. OUCH Quote Link to comment Share on other sites More sharing options...
deuces wild Posted March 24, 2005 Report Share Posted March 24, 2005 thanks for the heads up scuzzman! Quote Link to comment Share on other sites More sharing options...
mark2 Posted March 24, 2005 Report Share Posted March 24, 2005 oddly enough I was doing some cleaning up in my add/remove programs and had to get rid of the earlier FF references, so downloaded the newest version this morning.andsome said Just as I have said. As Firefox gets more popular, so attacks from the mindless will increase. I am sticking to IE.Andsome, the biggest problem regarding internet exploiter security wise is that it is integral to Windows, maybe FF will now start to be targeted the way IE is but the damage done will not go so deep into the OS and so easier to deal with. Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted March 25, 2005 Report Share Posted March 25, 2005 There is also a new version of Mozilla Thunderbird available from http://www.mozilla.org/What's New in Thunderbird 1.0.2Thunderbird 1.0.2 is a security and stability update that is part of our ongoing program to provide a safe Internet experience for our customers. We recommend that all users upgrade to this latest version.Important NoteTo avoid crashes or other problems, do not install a new version using the installer into the same folder as an older zipped installation.Full details here. Quote Link to comment Share on other sites More sharing options...
Wilt Posted March 25, 2005 Report Share Posted March 25, 2005 Or exploted :unsure: :lol:If you mean exploited, heaven forbid. OUCHThats the oneI need a new dictionary. Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted March 30, 2005 Report Share Posted March 30, 2005 Or exploted :unsure: :lol:If you mean exploited, heaven forbid. OUCHThats the oneI need a new dictionary.Or spell checker. I use the SpellBound plugin for Firefox to verify all posts before submitting. Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted April 16, 2005 Report Share Posted April 16, 2005 Firefox 1.0.3 is now officially released: http://www.mozilla.org/What's New 1.0.3Firefox 1.0.3 is a security update that is part of our ongoing program to provide a safe Internet experience for our customers. We recommend that all users upgrade to this latest version.Here's what's new in Firefox 1.0.3:Several security fixesFix to improve update process. Quote Link to comment Share on other sites More sharing options...
deuces wild Posted April 16, 2005 Report Share Posted April 16, 2005 Thanks for the heads up. I just update to v1.03. It took a whole 15 seconds and I did not have to uninstall v 1.02. Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 16, 2005 Report Share Posted April 16, 2005 The biggest problem regarding Internet Explorer security wise is that it is integral to Windows, maybe FF will now start to be targeted the way IE is but the damage done will not go so deep into the OS and so will be easier to deal with.Having read a similar comment elsewhere, this is what made me change over to Firefox. After using it for a couple of weeks I prefer it now anyway! Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted April 16, 2005 Report Share Posted April 16, 2005 Thanks for the heads up. I just update to v1.03. It took a whole 15 seconds and I did not have to uninstall v 1.02.Me too. I was surprised that the old version didn't have to be uninstalled first! :huh: Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted April 17, 2005 Report Share Posted April 17, 2005 I was surprised that the old version didn't have to be uninstalled first! :huh:Yes, the Windows installation is one of the things they fixed for 1.0.3 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.