Computing.Net > Forums > Security and Virus > Mozilla patches faulty patch

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Mozilla patches faulty patch

Reply to Message Icon

Original Message
Name: IronMan
Date: March 7, 2007 at 23:28:54 Pacific
Subject: Mozilla patches faulty patch
OS: XP Pro
CPU/Ram: P4 / 512m
Manufacturer/Model: Data General
Comment:

From the Register. . .

The Mozilla Foundation has patched a faulty patch that was itself subject to a security vulnerability.

A security update for Firefox and the SeaMonkey application suite issued in mid-December left users open to a JavaScript-related privilege escalation flaw that meant hackers could commandeer vulnerable machines, Mozilla warned on Monday.

The security bug affecting Firefox 1.5.0.9 and 2.0.0.1 as well as SeaMonkey 1.0.7 meant code designed to fix earlier flaws introduced a critical vulnerability. This vulnerability, which allowed scripts from web content to execute arbitrary code, was arguably worse than the bugs it tried to resolve because simply disabling JavaScript does not protect against the flaw.

FULL STORY


Report Offensive Message For Removal


Response Number 1
Name: XpUser
Date: March 8, 2007 at 08:58:06 Pacific
Reply:

What else is new? Mozilla has just adopted M$ tradition of screwing up windows patches :-)

i_XpUser


Report Offensive Follow Up For Removal

Response Number 2
Name: soupnasty
Date: March 8, 2007 at 14:24:07 Pacific
Reply:

Old news, this was fixed last week. It also was released the day after the flaw was found as well. You will not get taht sort of quick responce from M$.


Report Offensive Follow Up For Removal

Response Number 3
Name: Derek
Date: March 8, 2007 at 15:42:01 Pacific
Reply:

May I ask a question please?

I'm not a Firefox user (although I have nothing against their browser) but at one time you used to have to install a new Firefox version to fix each security issue.

Do they now, as a general rule, issue add-on security patches MS style (but quicker maybe LOL)?

Just educating myself....

DerekW


Report Offensive Follow Up For Removal

Response Number 4
Name: soupnasty
Date: March 8, 2007 at 17:25:31 Pacific
Reply:

It just updated Firefox with the patch. You also can downloaad the full version of FF 2.0.0.2


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: Mozilla patches faulty patch

virus alert!!!!!
    Summary: nortons alert on swen it sounds bad becarefull What is W32.Swen.A@mm and how does it affect me? W32.Swen.A@mm is a mass-mailing worm that uses its own SMTP engine to spread itself. It attempts to spre...
www.computing.net/answers/security/virus-alert/6536.html

virus alert!!
    Summary: Today's roundup of virus alerts: W32/Dumaru-E - Another worm that spreads under the guise of a Microsoft-issued patch. Like previous variants, the infected message looks like it's from " <mailto:...
www.computing.net/answers/security/virus-alert/6650.html

virus alert!!
    Summary: Today's roundup of virus alerts: W32/Dumaru-B - Another worm that spreads via an e-mail that claims to be a Microsoft patch. The infected message comes from " <mailto:security@microsoft.com> " wi...
www.computing.net/answers/security/virus-alert/6609.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software