This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Firefox 1.0.7 released!

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Firefox 1.0.7 is a security and stability release.
We strongly recommend that all users upgrade to this latest version.

This version includes several security and stability fixes, including a fix for a reported buffer overflow vulnerability and a fix for a Linux shell command vulnerability.

Specific changes in Firefox 1.0.7
  • Fix for a potential buffer overflow vulnerability when loading a hostname with all soft-hyphens
  • Fix to prevent URLs passed from external programs from being parsed by the shell (Linux only)
  • Fix to prevent a crash when loading a Proxy Auto-Config (PAC) script that uses an "eval" statement
  • Fix to restore InstallTrigger.getVersion() for Extension authors
  • «Other Stability & Security Fixes»
«Release Notes & Installation Instructions» |«Download»
FYI…

Attack code published for Firefox flaw
- http://news.com.com/Attack+code+published+…_3-5877903.html
September 22, 2005
" Computer code that could be used to attack Firefox, Mozilla Suite and Netscape users has been released on the Internet. The release of the attack code comes days after Mozilla released an updated version of Firefox to fix several security flaws, including the bug exploited by the code. A fixed version of the Mozilla Suite is also available, but Firefox-based Netscape has yet to be updated. The Netscape browser is a product of Netscape, which is a division of Time Warner's America Online subsidiary. An AOL spokesman had no comment on Thursday. The attack code exploits a vulnerability that was disclosed two weeks ago. The flaw lies in the way the browsers handle International Domain Names, or IDNs, which are Web addresses that use international characters. Hackers had been working to exploit the flaw and had said the code would be released after fixes were available. The exploit could let attackers run code remotely on vulnerable computers and works on Firefox, Mozilla and, in some cases, Netscape, according to security researcher Berend-Jan Wever, who published the code. Mozilla has urged users to upgrade to the latest versions of its products."

:(
Mozillazine
PwnZilla 5 Exploit
Thursday September 22nd, 2005

The exploit, created by Berend-Jan "SkyLined" Wever, can be used against vulnerable versions of Mozilla Firefox, the Mozilla Application Suite and Netscape Browser 8.

The latest Firefox 1.0.7 and Mozilla 1.7.12 releases, which have been made available over the past few days, are not affected as they both include a fix for the flaw. However, there is no fix available for Netscape Browser 8 (currently on version 8.0.3.3), though the exploit apparently works less reliably with this browser.

http://www.mozillazine.org/talkback.html?article=7400