Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Exploit code chases two Firefox flaws (May 9, 2005)
ZDnet ^ | May 9, 2005 | Dawn Kawamotot

Posted on 12/12/2005 8:14:49 PM PST by CometBaby

If you use the Firefox browser .. read this !! .. Two vulnerabilities in the popular Firefox browser have been rated "extremely critical" because exploit code is now available to take advantage of them. The cross-site scripting and remote system access flaws were discovered in Firefox version 1.0.3, but other versions may also be affected, said security company Secunia, which issued the ratings Sunday.

(Excerpt) Read more at news.zdnet.com ...


TOPICS:
KEYWORDS: exploit; firefox

1 posted on 12/12/2005 8:14:50 PM PST by CometBaby
[ Post Reply | Private Reply | View Replies]

To: CometBaby

I'm using Firefox 1.5


2 posted on 12/12/2005 8:16:38 PM PST by demlosers
[ Post Reply | Private Reply | To 1 | View Replies]

To: CometBaby

Who is still using 1.0.3????


3 posted on 12/12/2005 8:18:08 PM PST by clee1 (We use 43 muscles to frown, 17 to smile, and 2 to pull a trigger. I'm lazy and I'm tired of smiling.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CometBaby
Oh, great, I just started using Firefox.

I dumped AOL (and in response, my bank and I are battling it out, because AOL kept charging my closed bank account, and the bank kept paying!!!!!), and the other browser I tried kept refusing to open certain pages. I have no idea what's the best browser, but this one seems to work ok.

4 posted on 12/12/2005 8:19:02 PM PST by Darkwolf377 (An agnostic who never, ever says "Happy Holidays")
[ Post Reply | Private Reply | To 1 | View Replies]

To: clee1

Someone still living in May 2005, apparently.


5 posted on 12/12/2005 8:19:45 PM PST by Sols
[ Post Reply | Private Reply | To 3 | View Replies]

To: clee1
Who is still using 1.0.3????

LOL, ya, that is like finding someone still driving a Pinto.

6 posted on 12/12/2005 8:20:19 PM PST by New Perspective (Proud father of an 2 year old son with Down Syndrome)
[ Post Reply | Private Reply | To 3 | View Replies]

To: demlosers

...which appears to be rather unstable, although the crappy plugins I'm using could be to blame perhaps. Seems like no nifty new feature comes without 5 major regressions in the program.


7 posted on 12/12/2005 8:20:30 PM PST by dr_who_2
[ Post Reply | Private Reply | To 2 | View Replies]

To: CometBaby

This is absolutely ancient and fixed long ago


8 posted on 12/12/2005 8:20:57 PM PST by Mount Athos
[ Post Reply | Private Reply | To 1 | View Replies]

To: CometBaby
I warned all the anti-Microsoft people a long time ago not to gloat too much over Internet Explorer's flaws because the same will happen to FireFox.

The more people use it, the more vulnerabilities will be revealed.  Pure common sense.

9 posted on 12/12/2005 8:21:00 PM PST by softwarecreator (Facts are to liberals as holy water is to vampires.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dr_who_2

Because it's still in Beta release.


10 posted on 12/12/2005 8:21:59 PM PST by demlosers
[ Post Reply | Private Reply | To 7 | View Replies]

To: dr_who_2

Anything wrong with the way Firefox displays a website is the problem of the person who built that site. Not Firefox.


11 posted on 12/12/2005 8:22:03 PM PST by Sols
[ Post Reply | Private Reply | To 7 | View Replies]

To: clee1
Who is still using 1.0.3????

Someone who doesn't want to ever download and use any other extensions than the ones they have already installed?

12 posted on 12/12/2005 8:22:05 PM PST by Bloody Sam Roberts (This is my tagline. There are many like it but this one is mine.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: clee1

1.0.7


13 posted on 12/12/2005 8:22:53 PM PST by My2Cents (Dead people voting is the closest the Democrats come to believing in eternal life.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: demlosers

No it's not.


14 posted on 12/12/2005 8:23:03 PM PST by Sols
[ Post Reply | Private Reply | To 10 | View Replies]

To: dr_who_2
...which appears to be rather unstable

I was reluctant to upgrade. But I did. It's been just as stable for me as 1.0.7. No problems at all yet.

15 posted on 12/12/2005 8:23:51 PM PST by Bloody Sam Roberts (This is my tagline. There are many like it but this one is mine.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Sols
Not very long ago:

Mozilla Firefox 1.5 Released

Tuesday November 29th, 2005

The final release of Mozilla Firefox 1.5 is now available for download from GetFirefox.com for most major operating systems or from the mirrors. Users of the release candidates should receive the update soon.

http://www.mozillazine.org/talkback.html?article=7736

16 posted on 12/12/2005 8:27:04 PM PST by demlosers
[ Post Reply | Private Reply | To 14 | View Replies]

To: demlosers
I'm running Firefox 1.5 as well .. you have to go in and clean our your History cache and set it to store for zero days. What I am hearing, is that it is presently affecting all versions .. even this newest one. They are working hard on a patch.

Here is the official statement from Firefox: http://www.mozilla.org/security/history-title.html

Also, a warning has now come out for Opera .. apparently the same problem. Here is the story on Opera: http://secunia.com/advisories/17963/

17 posted on 12/12/2005 8:27:28 PM PST by CometBaby (You can twist perceptions .. reality won't budge!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: demlosers

So what you're saying is, 1.5 is not in beta. Which is what I said. ;)


18 posted on 12/12/2005 8:28:43 PM PST by Sols
[ Post Reply | Private Reply | To 16 | View Replies]

To: Mount Athos
This is absolutely ancient and fixed long ago

If you think this is ancient, read the official statement from Firefox

http://www.mozilla.org/security/history-title.html

19 posted on 12/12/2005 8:29:50 PM PST by CometBaby (You can twist perceptions .. reality won't budge!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Sols
Well, it was the last time I looked before a few minutes ago...time flies
20 posted on 12/12/2005 8:31:54 PM PST by demlosers
[ Post Reply | Private Reply | To 18 | View Replies]

To: CometBaby

The history title issue is in no way related to the very old iframe and InstallTrigger bugs. They are two entirely different things. An article from MAY 2005 is in fact ancient news in DECEMBER 2005.

Hello folks, let's read the article we're discussing, please.


21 posted on 12/12/2005 8:34:17 PM PST by Sols
[ Post Reply | Private Reply | To 19 | View Replies]

To: CometBaby
Ummm.... The article you posted is from May. That's like seven months ago. In case you missed it, Mozilla fixed this almost immediately. (As opposed to myriads of IE flaws that MS knows about but takes years to fix...)

Maybe some attention to date would be in order, since this certainly is not 'breaking' news!

22 posted on 12/12/2005 8:36:31 PM PST by NoCmpromiz (John 14:6 is a non-pluaralistic statement.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: softwarecreator
The most important thing that Firefox did was break Microsoft's monopoly on the browser. Now IE has popup blocking and the next version they will have tabs. Other features will follow. This is a good thing. While I have no problem with a natural monopoly, I believe that Microsoft abused their monopoly with the browser wars. Now that the browser wars have started again the quality of web browsers has skyrocketed. Microsoft is even faster on fixing security problems.

I use Firefox because I can't live without tabs and a reasonable popup blocker. If Microsoft makes a better browser I may switch (though they are probably about a year and a half behind right now).
23 posted on 12/12/2005 8:39:16 PM PST by burzum (Great minds discuss ideas, average minds discuss events, small minds discuss people.-Adm H Rickover)
[ Post Reply | Private Reply | To 9 | View Replies]

To: CometBaby

Because Firefox has no auto-update function, there are lots of people still using older versions. This security problem will be real if the Microsoft hating virus writers divert their hate for a few seconds.

Of course, that will not happen.


24 posted on 12/12/2005 8:43:04 PM PST by Poser (Willing to fight for oil)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Admin Moderator

You might want to consider moving this from 'latest news' since it is from May, and is no longer an issue...


25 posted on 12/12/2005 8:43:25 PM PST by NoCmpromiz (John 14:6 is a non-pluaralistic statement.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sols
You may be right about that .. I don't recall anything from May. I only know that this is some form of exploit because I was *punked*. I am no techie .. but I am not exactly a newbie as my client is on the net 24/7.

Today I had problems with the slow bootup, and my computer was hanging (I have a P4 with 1 gig of memory)so there is no reason it should.

To make a long story short, I went in and cleared my history cache, set my saved days to zero .. problem gone.

26 posted on 12/12/2005 8:43:46 PM PST by CometBaby (You can twist perceptions .. reality won't budge!)
[ Post Reply | Private Reply | To 21 | View Replies]

To: CometBaby
I'm running Firefox 1.5 as well .. you have to go in and clean our your History cache and set it to store for zero days. What I am hearing, is that it is presently affecting all versions .. even this newest one. They are working hard on a patch.

Will do. Thanks :)

27 posted on 12/12/2005 8:47:49 PM PST by demlosers
[ Post Reply | Private Reply | To 17 | View Replies]

To: softwarecreator

Maybe you should warn secunia about hyping problems with a very old version of firefox.


28 posted on 12/12/2005 8:51:30 PM PST by flashbunny (To err is human. But to really screw something up, have the government try to fix it.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Poser
In the News/Activism forum, on a thread titled Exploit code chases two Firefox flaws, Poser wrote:

Because Firefox has no auto-update function, there are lots of people still using older versions. This security problem will be real if the Microsoft hating virus writers divert their hate for a few seconds.

Of course, that will not happen.

FireFox DOES auto-update ... if/when a little red circle with an up-arrow appears on the right-hand end the menu bar, just give it a single click. Couldn't be easier ...

29 posted on 12/12/2005 8:54:07 PM PST by cooldog (Islam is a criminal conspiracy to commit mass murder ... deal with it!)
[ Post Reply | Private Reply | To 24 | View Replies]

To: CometBaby

I'll just switch back to my Firebird 0.7 version. That should be safe.


30 posted on 12/12/2005 8:54:15 PM PST by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: CometBaby
The link

<a href-"http://www.mozilla.org/security/history-title.html>(text goes here)</a>

31 posted on 12/12/2005 9:00:03 PM PST by spunkets
[ Post Reply | Private Reply | To 17 | View Replies]

To: CometBaby

Version 1 Firefox browser is already on 1.07


32 posted on 12/12/2005 9:05:47 PM PST by thoughtomator (What'ya mean you formatted the cat!?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: demlosers

I'm at 1.0.7


33 posted on 12/12/2005 9:06:24 PM PST by b4its2late (The only substitute for good manners is faster reflexes.)
[ Post Reply | Private Reply | To 2 | View Replies]

I'm not using Firefox, per se......

I'm using Mozilla 1.7.11, and it's working flawlessly.


34 posted on 12/12/2005 9:42:59 PM PST by John Williams ("Mommy is no longer with us. The Republican Party is now a single parent.")
[ Post Reply | Private Reply | To 33 | View Replies]

To: cooldog
"FireFox DOES auto-update ... if/when a little red circle with an up-arrow appears on the right-hand end the menu bar, just give it a single click. Couldn't be easier"


You are describing something I have never seen. Are you running Linux?
35 posted on 12/13/2005 6:51:02 AM PST by Poser (Willing to fight for oil)
[ Post Reply | Private Reply | To 29 | View Replies]

To: flashbunny
Maybe you should warn secunia about hyping problems with a very old version of firefox

HAHAHA.  Your'e probably right, but a lot of people are already making that suggestion!

36 posted on 12/13/2005 3:25:35 PM PST by softwarecreator (Facts are to liberals as holy water is to vampires.)
[ Post Reply | Private Reply | To 28 | View Replies]

To: Sols

Any website that can kill firefox is Firefox's problem.


37 posted on 12/13/2005 4:49:34 PM PST by dr_who_2
[ Post Reply | Private Reply | To 11 | View Replies]

To: Poser
I run Firefox on both WinXP and Linux. Let me see if I can find some info for you ....

Here you go: Firefox update info

38 posted on 12/14/2005 8:25:06 AM PST by cooldog (Islam is a criminal conspiracy to commit mass murder ... deal with it!)
[ Post Reply | Private Reply | To 35 | View Replies]

To: Poser
You are describing something I have never seen. Are you running Linux?

I am on XP and i tnotifies me of an available update as well.

39 posted on 12/14/2005 8:29:03 AM PST by smith288 (Peace at all cost makes for tyranny free of charge...)
[ Post Reply | Private Reply | To 35 | View Replies]

To: smith288

Thanks.

It was so small I never noticed it before.


40 posted on 12/14/2005 10:31:10 AM PST by Poser (Willing to fight for oil)
[ Post Reply | Private Reply | To 39 | View Replies]

To: Mount Athos; Bloody Sam Roberts; demlosers; Sols; NoCmpromiz; flashbunny
Here is an explanation on the exploit dated Dec 8, 2005 (very recent) about this exploit ..

"Unpatched Firefox 1.5 exploit made public" .

The way it affected me is becuase I leave my browser open and when I came back in the morning, it was chucking down 2GB of ram.

http://news.com.com/Unpatched+Firefox+1.5+exploit+made+public/2100-1002_3-5987401.html

41 posted on 12/14/2005 6:24:03 PM PST by CometBaby (You can twist perceptions .. reality won't budge!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: CometBaby

from your link:

"Correction: This story incorrectly stated the affiliation of Mike Schroepfer. It also misstated Mozilla's results in verifying the Firefox 1.5 flaw. The problem itself was not a security vulnerability but actually a flaw in the browser, according to Mozilla. In addition, it misstated PacketStorm's assessment of the situation."


42 posted on 12/14/2005 6:32:34 PM PST by flashbunny (To err is human. But to really screw something up, have the government try to fix it.)
[ Post Reply | Private Reply | To 41 | View Replies]

To: CometBaby
What you described, it looks like Firefox has a "memory leak."
43 posted on 12/14/2005 6:52:22 PM PST by demlosers
[ Post Reply | Private Reply | To 41 | View Replies]

To: CometBaby
Except that the exploit you reference is not the subject of the ZDNet article from May. Here is Mozilla's official response to the current issue:

Long-title temporary startup unresponsiveness

44 posted on 12/15/2005 5:01:46 PM PST by NoCmpromiz (John 14:6 is a non-pluaralistic statement.)
[ Post Reply | Private Reply | To 41 | View Replies]

To: cooldog

How do I know which version I'm using?
I never get popups with Firefox. But I do have trouble using Cookies on it. Sometimes I want to accept something but I had at another time denied its cookie. Firefox could be easier with this. I use Cookie Pal for IE and it's easy to wipe up after.
I have more complaints about Gmail (can't edit anymore and can't link anymore).


45 posted on 12/15/2005 5:09:21 PM PST by The Westerner
[ Post Reply | Private Reply | To 29 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson