IMPORTANT Security Update for Firefox 1.0PR

Shagga

Diamond Member
Nov 9, 1999
4,421
0
76
Check out Warp2Search for the ditty.

[edit]

Mozilla News Update and the Direct Patch

Important Security Update for Firefox Available

October 1, 2004. The Mozilla Foundation releases an important security update for Firefox. All users should upgrade to the latest version of the Firefox Preview Release. A patch is available for current Preview Release users.

Download information:

* Visit the Firefox homepage to download the latest version of Firefox Preview Release (Firefox 0.10.1)
* Current Firefox Preview Release users: when the update icon () appears in the upper right corner of your screen, just click on it to install the patch, or click here to install it.

Questions & Answers:

*

How does this security vulnerability expose the user?

A malicious hacker who could trick a user into saving a file could delete files from a user's download directory.
*

How serious is this vulnerability?

While this is a potentially severe security vulnerability, user interaction is required to trigger potential harm. This security update is also another example of the Mozilla Foundation identifying and fixing security vulnerabilities before they are exploited by malicious hackers. This type of security vulnerability is very different from cases where a hacker could take advantage of a vulnerability to obtain valuable information from a user's computer.
*

Doesn't this case illustrate that all browsers are equally insecure?

The Mozilla Foundation continues to have a very strong track record on security. According to Secunia, an independent security monitoring organization, Firefox currently has 1 open security issue, out of a total of 13 security advisories filed in 2003 and 2004. 0% of these are labeled "extremely critical", 15% are labeled "highly critical". For the same period, Secunia lists 16 open security issues out of 44 advisories for Internet Explorer 6.0, 14% of which are labeled "extremely critical", 34% are "highly critical".
 

Lonyo

Lifer
Aug 10, 2002
21,938
6
81
I saw the little "updates available" thing in the top right and downloaded the fix.
I like that feature. It's not intrusive like the MS Windows update.
 

Koing

Elite Member <br> Super Moderator<br> Health and F
Oct 11, 2000
16,843
2
0
Done.

Thanks.

Koing
 

Sid59

Lifer
Sep 2, 2002
11,879
3
81
ooh thanks. i actually got around to updating FF on my 2nd PC and gf's PC. The PR from today covered it.

thanks again.
 

XBoxLPU

Diamond Member
Aug 21, 2001
4,249
1
0
been using mozilla 1.7 lately

I guess I will go back to FireFox once 1.0 is out

thanks anyway though
 

Bateluer

Lifer
Jun 23, 2001
27,730
8
0
How do you apply the direct patch since the auto DL/Install doesn't work for me? Windows doesn't recognize and xpi file.
 

jfall

Diamond Member
Oct 31, 2000
5,975
2
0
Originally posted by: Bateluer
How do you apply the direct patch since the auto DL/Install doesn't work for me? Windows doesn't recognize and xpi file.

tools > options > web features > allow websites to install software -- do you have this checked?
 

Bateluer

Lifer
Jun 23, 2001
27,730
8
0
Originally posted by: jfall
Originally posted by: Bateluer
How do you apply the direct patch since the auto DL/Install doesn't work for me? Windows doesn't recognize and xpi file.

tools > options > web features > allow websites to install software -- do you have this checked?

Seems to work thru the auto update when I check it.
I usually keep it unchecked. Since the Red alert marker is now gone and the version is listed as .10.1, it looks like its installed now.
 

XBoxLPU

Diamond Member
Aug 21, 2001
4,249
1
0
I also think you can download the XPI, highlight the file, and then drag and drop the XPI into Firefox....
 

rh71

No Lifer
Aug 28, 2001
52,844
1,049
126
damn I thought this thing was superior to IE !!!!!!!! WTF is the point if I still have to patch it just the same ???

<-- goes back to IE. ;)

(FF fanboys can save it... I just like to poke fun when I get the chance) ... updating FF now. :|
 

rh71

No Lifer
Aug 28, 2001
52,844
1,049
126
Umm... the XPI doesn't do the upgrade. It brings up a box for DOM Inspector and the first time it said "download error" ... the second time it doesn't even do anything when I click update. mozilla.org doesn't even have 1.01 or 0.10.1 (whatever they feel like calling it) for download right now. Free Download points to 1.0PR.exe still... unless that is 1.01. I have a better idea... why don't they make this harder for us ?
 

Shagga

Diamond Member
Nov 9, 1999
4,421
0
76
As I understand it the 1.0PR.exe files has been updated. So, in theory you could just DL the full thing again. :frown: