This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Firefox 1.0.5 released

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/wire/software/165701816
July 12, 2005
"…A month ago, Danish security firm Secunia announced that most browsers, including the then-current Firefox 1.0.4, were vulnerable to a JavaScript spoofing error that could let attackers steal passwords and other confidential data. Although a Mozilla spokesperson said that 1.0.5 fixed the problem, TechWeb ran the browser through Secunia's vulnerability test and found that it still failed ( http://secunia.com/multiple_browsers_dialo…erability_test/ ). However, this edition does fix the frame injection vulnerability that had crept back into the Firefox code in versions 1.0.3 and 1.0.4…"

:huh: :blink:
FYI…(now posted):

Fixed in Firefox 1.0.5
- http://www.mozilla.org/projects/security/k…es.html#Firefox
MFSA 2005-56 Code execution through shared function objects
MFSA 2005-55 XHTML node spoofing
MFSA 2005-54 Javascript prompt origin spoofing
MFSA 2005-53 Standalone applications can run arbitrary code through the browser
MFSA 2005-52 Same origin violation: frame calling top.focus()
MFSA 2005-51 The return of frame-injection spoofing
MFSA 2005-50 Possibly exploitable crash in InstallVersion.compareTo()
MFSA 2005-49 Script injection from Firefox sidebar panel using data:
MFSA 2005-48 Same-origin violation with InstallTrigger callback
MFSA 2005-47 Code execution via "Set as Wallpaper"
MFSA 2005-46 XBL scripts ran even when Javascript disabled
MFSA 2005-45 Content-generated event vulnerabilities

:ph34r: