Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Mozilla Says Firefox 1.5 Bug Not Serious
TechWeb News ^ | December 12, 2005 | Greg Keizer

Posted on 12/12/2005 10:15:30 AM PST by Eagle9

Mozilla Corp. has warned users of its newest browser, Firefox 1.5, that a bug in how the software handles extremely long names can make it seem that the computer has crashed. The flaw, however, does not expose users to attack, contrary to earlier reports by researchers.

Malicious pages with very long titles--the proof of concept for the pseudo denial-of-service (DoS) attack contained 2.5 million characters--make the browser appear to hang, said Mozilla in an online security advisory, although the software is actually busy processing the name. Once encountered, the very slow start can't be corrected until the site name is removed from Firefox's history file.

Last week, researchers of the PacketStorm security group claimed that the bug could result in not just a DoS, but a more serious buffer overflow, which could be used in turn by attackers to compromise the system.

Mozilla, however, said that additional investigations showed that there is no danger of a buffer overflow. "We can find no basis for claims that variants of this denial-of-service attack can cause an exploitable crash," stated the Mozilla advisory. "There does not appear to be any risk to users or their computers beyond the temporary unresponsiveness at startup."

The advisory also includes instructions on clearing the history file of the too-long site name.

Mozilla has not set a release date for a fix.


TOPICS: Technical
KEYWORDS: browser; firefox; mozilla
Navigation: use the links below to view more comments.
first previous 1-2021-29 last
To: Hank Rearden; All

I don't have an answer, but the fact you say you have a lot of bookmarks leads me to ask if you do or how you back your stuff up. If you don't have this, get it, since it's free:

http://mozbackup.jasnapaka.com/

It works with FF and the Mozilla suite and T-bird.

One of my biggest gripes is how FF has had a bookmark problem for who knows how long, and they've yet to address it.


21 posted on 12/12/2005 5:24:04 PM PST by JoJo Gunn (Help control the Leftist population. Have them spayed or neutered. ©)
[ Post Reply | Private Reply | To 15 | View Replies]

To: George from New England; M0sby; Hank Rearden; tubebender; JerseyHighlander; Big Giant Head; All
I've been using Firefox since the 0.7 version when it was named Firebird. I have no technical training or background other than what little I've been able to learn from others when they were using terms that I understood. This 1.5 version of Firefox has some major changes, which the developers tried to test and have most of the wrinkles ironed out before releasing it out of beta. The real acid test is to release it to the average Internet user and then resolve the remaining issues that are reported by way of complaints, either with a work around or a patch. Those of you here who haven't visited the Mozilla Firefox Forum might want to consider doing so and maybe you'll see a topic that fits your particular problem. You can read without registering, or register and ask specific questions. It's no different than posting here at FR. I would help if I could but those who worked on the developement of this version of Firefox are who I would post my questions to if I were having problems. Fortunately for me, 1.5 is running fast with no major problems. Below is the link to the Mozilla Firefox Forum.

http://forums.mozillazine.org/viewforum.php?f=38

I'm not saying don't post questions here, just giving those who don't know another place to look for answers if none are found here at FR.

22 posted on 12/12/2005 6:18:08 PM PST by Eagle9
[ Post Reply | Private Reply | To 1 | View Replies]

To: Big Giant Head
That web site loads for me in FF 1.5. I have Flash blocked but allowed it to load and it played as it should.The solution to your particular problem is explained at the following linked web page. It depends on what version of Windows you're running.

http://forums.mozillazine.org/viewtopic.php?t=320838

23 posted on 12/12/2005 11:05:23 PM PST by Eagle9
[ Post Reply | Private Reply | To 20 | View Replies]

To: M0sby

See #16 by chronic_loser. Need more info to help.


24 posted on 12/12/2005 11:08:38 PM PST by Eagle9
[ Post Reply | Private Reply | To 14 | View Replies]

To: chronic_loser
Thank you CL...
We defrag every Wed and Virus "stuff" (norton corporate is updated weekly too.)
I don't know if this is the "fixit" utility that you mentioned?
I don't know about the RAM part..

I will ask my husband.
He is a HUGE computer GEEK..but isn't running Firefox which is why I thought I would ask you guys instead of him! LOL!
(It is possible that I may have offended his computer geek manly-hood though ;-)

Anyway...the other thing I run into is a HUGE lag-time when I open the program (by double clicking on the desktop icon)

AND...if I leave the program "open" and minimized for a long period (like overnight) sometimes it "sort of" hangs...is very slow and I might have to "force quit" to get out and reopen..

Just wondering if other people are having these "issues"...

THANKS for your FAST reply last time!
Sorry mine WASN'T!
25 posted on 12/13/2005 6:37:32 AM PST by M0sby (((PROUD WIFE of MSgt Edwards USMC)))
[ Post Reply | Private Reply | To 16 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...
Here's more information on the flaw.

It appears that the flaw is actually concerned with the history.dat file as opposed to the actual long website name.

26 posted on 12/13/2005 9:31:34 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Eagle9

It worked for a few hours.


27 posted on 12/13/2005 11:01:09 AM PST by BallyBill (U.S. Armed Forces.. In It ..To Win It!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

Hey thanks Eagle9! That worked.


28 posted on 12/13/2005 7:32:16 PM PST by Big Giant Head (I should change my tagline to "Big Giant Pancake on my Head")
[ Post Reply | Private Reply | To 23 | View Replies]

To: chronic_loser
The problem is the markup's TITLE attribute (in html, the stuff between the <TITLE></TITLE> tags) not the URL.
29 posted on 12/18/2005 6:42:34 AM PST by dwollmann
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-29 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson