Skip to comments.
Exploit code chases two Firefox flaws (May 9, 2005)
ZDnet ^
| May 9, 2005
| Dawn Kawamotot
Posted on 12/12/2005 8:14:49 PM PST by CometBaby
If you use the Firefox browser .. read this !! .. Two vulnerabilities in the popular Firefox browser have been rated "extremely critical" because exploit code is now available to take advantage of them. The cross-site scripting and remote system access flaws were discovered in Firefox version 1.0.3, but other versions may also be affected, said security company Secunia, which issued the ratings Sunday.
(Excerpt) Read more at news.zdnet.com ...
TOPICS:
KEYWORDS: exploit; firefox
1
posted on
12/12/2005 8:14:50 PM PST
by
CometBaby
To: CometBaby
2
posted on
12/12/2005 8:16:38 PM PST
by
demlosers
To: CometBaby
Who is still using 1.0.3????
3
posted on
12/12/2005 8:18:08 PM PST
by
clee1
(We use 43 muscles to frown, 17 to smile, and 2 to pull a trigger. I'm lazy and I'm tired of smiling.)
To: CometBaby
Oh, great, I just started using Firefox.
I dumped AOL (and in response, my bank and I are battling it out, because AOL kept charging my closed bank account, and the bank kept paying!!!!!), and the other browser I tried kept refusing to open certain pages. I have no idea what's the best browser, but this one seems to work ok.
4
posted on
12/12/2005 8:19:02 PM PST
by
Darkwolf377
(An agnostic who never, ever says "Happy Holidays")
To: clee1
Someone still living in May 2005, apparently.
5
posted on
12/12/2005 8:19:45 PM PST
by
Sols
To: clee1
Who is still using 1.0.3????LOL, ya, that is like finding someone still driving a Pinto.
6
posted on
12/12/2005 8:20:19 PM PST
by
New Perspective
(Proud father of an 2 year old son with Down Syndrome)
To: demlosers
...which appears to be rather unstable, although the crappy plugins I'm using could be to blame perhaps. Seems like no nifty new feature comes without 5 major regressions in the program.
7
posted on
12/12/2005 8:20:30 PM PST
by
dr_who_2
To: CometBaby
This is absolutely ancient and fixed long ago
To: CometBaby
I warned all the anti-Microsoft people a long time ago not to gloat too much over Internet Explorer's flaws because the same will happen to FireFox.
The more people use it, the more vulnerabilities will be revealed. Pure common sense.
9
posted on
12/12/2005 8:21:00 PM PST
by
softwarecreator
(Facts are to liberals as holy water is to vampires.)
To: dr_who_2
Because it's still in Beta release.
To: dr_who_2
Anything wrong with the way Firefox displays a website is the problem of the person who built that site. Not Firefox.
11
posted on
12/12/2005 8:22:03 PM PST
by
Sols
To: clee1
Who is still using 1.0.3???? Someone who doesn't want to ever download and use any other extensions than the ones they have already installed?
12
posted on
12/12/2005 8:22:05 PM PST
by
Bloody Sam Roberts
(This is my tagline. There are many like it but this one is mine.)
To: clee1
13
posted on
12/12/2005 8:22:53 PM PST
by
My2Cents
(Dead people voting is the closest the Democrats come to believing in eternal life.)
To: demlosers
14
posted on
12/12/2005 8:23:03 PM PST
by
Sols
To: dr_who_2
...which appears to be rather unstable I was reluctant to upgrade. But I did. It's been just as stable for me as 1.0.7. No problems at all yet.
15
posted on
12/12/2005 8:23:51 PM PST
by
Bloody Sam Roberts
(This is my tagline. There are many like it but this one is mine.)
To: Sols
Not very long ago:
Mozilla Firefox 1.5 Released
Tuesday November 29th, 2005
The final release of Mozilla Firefox 1.5 is now available for download from GetFirefox.com for most major operating systems or from the mirrors. Users of the release candidates should receive the update soon.
http://www.mozillazine.org/talkback.html?article=7736
To: demlosers
I'm running Firefox 1.5 as well .. you have to go in and clean our your History cache and set it to store for zero days. What I am hearing, is that it is presently affecting all versions .. even this newest one. They are working hard on a patch.
Here is the official statement from Firefox: http://www.mozilla.org/security/history-title.html
Also, a warning has now come out for Opera .. apparently the same problem. Here is the story on Opera: http://secunia.com/advisories/17963/
17
posted on
12/12/2005 8:27:28 PM PST
by
CometBaby
(You can twist perceptions .. reality won't budge!)
To: demlosers
So what you're saying is, 1.5 is not in beta. Which is what I said. ;)
18
posted on
12/12/2005 8:28:43 PM PST
by
Sols
To: Mount Athos
This is absolutely ancient and fixed long agoIf you think this is ancient, read the official statement from Firefox
http://www.mozilla.org/security/history-title.html
19
posted on
12/12/2005 8:29:50 PM PST
by
CometBaby
(You can twist perceptions .. reality won't budge!)
To: Sols
Well, it was the last time I looked before a few minutes ago...time flies
To: CometBaby
The history title issue is in no way related to the very old iframe and InstallTrigger bugs. They are two entirely different things. An article from MAY 2005 is in fact ancient news in DECEMBER 2005.
Hello folks, let's read the article we're discussing, please.
21
posted on
12/12/2005 8:34:17 PM PST
by
Sols
To: CometBaby
Ummm.... The article you posted is from May. That's like seven months ago. In case you missed it, Mozilla fixed this almost immediately. (As opposed to myriads of IE flaws that MS knows about but takes years to fix...)
Maybe some attention to date would be in order, since this certainly is not 'breaking' news!
22
posted on
12/12/2005 8:36:31 PM PST
by
NoCmpromiz
(John 14:6 is a non-pluaralistic statement.)
To: softwarecreator
The most important thing that Firefox did was break Microsoft's monopoly on the browser. Now IE has popup blocking and the next version they will have tabs. Other features will follow. This is a good thing. While I have no problem with a natural monopoly, I believe that Microsoft abused their monopoly with the browser wars. Now that the browser wars have started again the quality of web browsers has skyrocketed. Microsoft is even faster on fixing security problems.
I use Firefox because I can't live without tabs and a reasonable popup blocker. If Microsoft makes a better browser I may switch (though they are probably about a year and a half behind right now).
23
posted on
12/12/2005 8:39:16 PM PST
by
burzum
(Great minds discuss ideas, average minds discuss events, small minds discuss people.-Adm H Rickover)
To: CometBaby
Because Firefox has no auto-update function, there are lots of people still using older versions. This security problem will be real if the Microsoft hating virus writers divert their hate for a few seconds.
Of course, that will not happen.
24
posted on
12/12/2005 8:43:04 PM PST
by
Poser
(Willing to fight for oil)
To: Admin Moderator
You might want to consider moving this from 'latest news' since it is from May, and is no longer an issue...
25
posted on
12/12/2005 8:43:25 PM PST
by
NoCmpromiz
(John 14:6 is a non-pluaralistic statement.)
To: Sols
You may be right about that .. I don't recall anything from May. I only know that this is some form of exploit because I was *punked*. I am no techie .. but I am not exactly a newbie as my client is on the net 24/7.
Today I had problems with the slow bootup, and my computer was hanging (I have a P4 with 1 gig of memory)so there is no reason it should.
To make a long story short, I went in and cleared my history cache, set my saved days to zero .. problem gone.
26
posted on
12/12/2005 8:43:46 PM PST
by
CometBaby
(You can twist perceptions .. reality won't budge!)
To: CometBaby
I'm running Firefox 1.5 as well .. you have to go in and clean our your History cache and set it to store for zero days. What I am hearing, is that it is presently affecting all versions .. even this newest one. They are working hard on a patch. Will do. Thanks :)
To: softwarecreator
Maybe you should warn secunia about hyping problems with a very old version of firefox.
28
posted on
12/12/2005 8:51:30 PM PST
by
flashbunny
(To err is human. But to really screw something up, have the government try to fix it.)
To: Poser
| In the News/Activism forum, on a thread titled Exploit code chases two Firefox flaws, Poser wrote: |
|
Because Firefox has no auto-update function, there are lots of people still using older versions. This security problem will be real if the Microsoft hating virus writers divert their hate for a few seconds.
Of course, that will not happen. |
FireFox DOES auto-update ... if/when a little red circle with an up-arrow appears on the right-hand end the menu bar, just give it a single click. Couldn't be easier ...
29
posted on
12/12/2005 8:54:07 PM PST
by
cooldog
(Islam is a criminal conspiracy to commit mass murder ... deal with it!)
To: CometBaby
I'll just switch back to my Firebird 0.7 version. That should be safe.
30
posted on
12/12/2005 8:54:15 PM PST
by
PAR35
To: CometBaby
31
posted on
12/12/2005 9:00:03 PM PST
by
spunkets
To: CometBaby
Version 1 Firefox browser is already on 1.07
32
posted on
12/12/2005 9:05:47 PM PST
by
thoughtomator
(What'ya mean you formatted the cat!?)
To: demlosers
33
posted on
12/12/2005 9:06:24 PM PST
by
b4its2late
(The only substitute for good manners is faster reflexes.)
I'm not using Firefox, per se......
I'm using Mozilla 1.7.11, and it's working flawlessly.
34
posted on
12/12/2005 9:42:59 PM PST
by
John Williams
("Mommy is no longer with us. The Republican Party is now a single parent.")
To: cooldog
"FireFox DOES auto-update ... if/when a little red circle with an up-arrow appears on the right-hand end the menu bar, just give it a single click. Couldn't be easier"
You are describing something I have never seen. Are you running Linux?
35
posted on
12/13/2005 6:51:02 AM PST
by
Poser
(Willing to fight for oil)
To: flashbunny
Maybe you should warn secunia about hyping problems with a very old version of firefoxHAHAHA. Your'e probably right, but a lot of people are already making that suggestion!
36
posted on
12/13/2005 3:25:35 PM PST
by
softwarecreator
(Facts are to liberals as holy water is to vampires.)
To: Sols
Any website that can kill firefox is Firefox's problem.
37
posted on
12/13/2005 4:49:34 PM PST
by
dr_who_2
To: Poser
I run Firefox on both WinXP and Linux. Let me see if I can find some info for you ....
Here you go: Firefox update info
38
posted on
12/14/2005 8:25:06 AM PST
by
cooldog
(Islam is a criminal conspiracy to commit mass murder ... deal with it!)
To: Poser
You are describing something I have never seen. Are you running Linux? I am on XP and i tnotifies me of an available update as well.
39
posted on
12/14/2005 8:29:03 AM PST
by
smith288
(Peace at all cost makes for tyranny free of charge...)
To: smith288
Thanks.
It was so small I never noticed it before.
40
posted on
12/14/2005 10:31:10 AM PST
by
Poser
(Willing to fight for oil)
To: Mount Athos; Bloody Sam Roberts; demlosers; Sols; NoCmpromiz; flashbunny
Here is an explanation on the exploit dated Dec 8, 2005 (very recent) about this exploit ..
"Unpatched Firefox 1.5 exploit made public" .
The way it affected me is becuase I leave my browser open and when I came back in the morning, it was chucking down 2GB of ram.
http://news.com.com/Unpatched+Firefox+1.5+exploit+made+public/2100-1002_3-5987401.html
41
posted on
12/14/2005 6:24:03 PM PST
by
CometBaby
(You can twist perceptions .. reality won't budge!)
To: CometBaby
from your link:
"Correction: This story incorrectly stated the affiliation of Mike Schroepfer. It also misstated Mozilla's results in verifying the Firefox 1.5 flaw. The problem itself was not a security vulnerability but actually a flaw in the browser, according to Mozilla. In addition, it misstated PacketStorm's assessment of the situation."
42
posted on
12/14/2005 6:32:34 PM PST
by
flashbunny
(To err is human. But to really screw something up, have the government try to fix it.)
To: CometBaby
What you described, it looks like Firefox has a "memory leak."
To: CometBaby
44
posted on
12/15/2005 5:01:46 PM PST
by
NoCmpromiz
(John 14:6 is a non-pluaralistic statement.)
To: cooldog
How do I know which version I'm using?
I never get popups with Firefox. But I do have trouble using Cookies on it. Sometimes I want to accept something but I had at another time denied its cookie. Firefox could be easier with this. I use Cookie Pal for IE and it's easy to wipe up after.
I have more complaints about Gmail (can't edit anymore and can't link anymore).
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson