• On CBSSports.com: Mike Tyson's daughter dies in accident

September 15, 2006 12:54 PM PDT

Firefox update patches security holes

  • 15 comments
Mozilla has sent out an update to Firefox, designed to address seven security flaws in the open-source Web browser.

Firefox 1.5.0.7, released Thursday, tackles a problem that lets outsiders run code remotely and aims to improve the product's stability.

Of the seven vulnerabilities fixed, four are rated "critical" by Mozilla. The new browser version addresses the circumvention of security via an RSA signature forgery flaw, as well as cross-site scripting vulnerabilities. In addition, it patches a JavaScript regular expression heap corruption issue and a memory corruption issue that could lead to the execution of code.

While the update addressed four critical flaws, it was less extensive than one released in July that contained fixes for seven flaws.

The release of Firefox 1.5.0.7 comes alongside the online publication of exploits to attack Microsoft's Internet Explorer. The 5.01 and 6 versions of the Web browser, running on all current versions of the Windows operating system, are affected.

See more CNET content tagged:
flaw, patch management, Firefox, Mozilla Corp., open source

Add a Comment (Log in or register) (15 Comments)
  • prev
  • 1
  • next
So why hasn't FF alerted me?
by ejevo September 15, 2006 1:18 PM PDT
FF can be a great browser, but I keep finding glitches that drag it back down to the level of IE, albeit not nearly as bad from a security standpoint, but not such that it can crow about its features, either.

Why does it take days before FF alerts to the fact that it has an update available? I should be finding out about updates available from the update feature, not from reading about them in the press a day after they've been released.
Reply to this comment
Worked for me.
by System Tyrant September 15, 2006 2:12 PM PDT
Mine downloaded and installed the upgrade last night. For me it's usually only a day before the update comes in.
some things to check ...
by Dalkorian September 15, 2006 2:58 PM PDT
If FF isn't updating itself for you, you can set it to do so. Confirm
the following settings:

Tools -> Options -> Advanced ->Update

1. Double-check that the checkbox next to Firefox is checked
(otherwise it's not looking for updates:)). I also have the others
checked as well ("Installed Extensions and Themes" as well as
"Search Engines").

2. Check the radio button next to either "Ask me what I want to
do" or "Automatically download and install update" for "When
updates to Firefox are found", depending on your preference (I
have mine to "Automatically download and install update", but
you might not want things happening behind your back :)).

3. Remember it's not likely to update itself unless it's running -
in other words if you haven't used FF over the last week (or only
used it for a few minutes at a time and then quit the program)
it's probably not tried to update itself yet, but should (silently)
do so when you fire it up. Also, consider what would happen to
Mozilla if all FF copies in the world hit their server
simutaneously. I'm sure they've mitigated against this by having
each copy pick a random day or time to check for updates, so
even if you have had it running 24/7 for the last month it might
not have "been it's time" yet.

Of course if you don't want to wait, you can "force" an update
anytime through the help menu.

Is FF the perfect browser? LOL. Software isn't perfect, that's a
simple fact of life. What's good about FF (besides being open
source and all that good stuff) is it isn't integrated perversely
with the OS like some other crapware browsers out there (yeah,
you KNOW what I'm talking about!). Oh, it tends to get fixed
faster too.
Strange
by SeizeCTRL September 15, 2006 4:05 PM PDT
I got the update notice Thursday around 9:30pm EST and had no idea it was coming out. That's why I love FF. Very quick to respond and get the patches out. IE you have to wait for patch Tuesday and for Microsoft Update to push it down to your PC. FF completely automatic!
Mine updated automatically
by Penguinisto September 18, 2006 1:43 PM PDT
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.7) Gecko/20060913 Fedora/1.5.0.7-1.fc5 Firefox/1.5.0.7 pango-text

It nicely informed me as soon as I had shut it off and re-started it today (shrug).
OMG!!!!!!!!!!!!!!!!!!
by Lindy01 September 15, 2006 2:16 PM PDT
Ditch FF and got to IE!!!!!!!!!!!!!!!! What shody, horrible open source JUNK!!!!!!!!!!!!!!!!!!

Stop the open source movement its run by Terror groups and they greatly contribute to global warming, and the third world starving!!!!!!!!!!!

Seriously...software is complicated and made by humans and will have bugs....whether its from MS or anyone else.

Compare the comments on this article to the other one today where IE had a new bug....it was a CNET, liberal, commie, MS Bash Fest!
Reply to this comment
Bookmarks bug
by sportav September 15, 2006 2:25 PM PDT
The bug on my XT box at work (Ugh) locks up the program when you simply hover over the bookmarks menu. Also, news videos on CNN and MSNBC do not run.
Reply to this comment
CNN videos don't even work for me in IE, never have
by mjm01010101 September 15, 2006 7:12 PM PDT
CNN videos don't even work for me in IE, never have

As for MSN, you must use IE for that.

Just go elsewhere for your videos, not like there isn't a plethora of sites that DO work.
Reply to this comment
Huh?
by groink_hi September 16, 2006 12:41 PM PDT
Looks like you posted under the wrong article. This article doesn't have anything to do with CNN, videos, or Internet Explorer.
What???
by cary1 September 18, 2006 7:11 AM PDT
I just played this one in IE and it worked:

http://www.cnn.com/video/player/player.html?url=/video/us/2006/09/18/sot.mo.missing.baby.grandparents.ksdk&wm=11

The video is in WMV format... It's not possible that it won't play in IE
Share police stories and news
by lucifinil September 17, 2006 11:28 PM PDT
Share police stories and news

Check the news from police.vost.com

military friends, military networking military network, military
social, finding friends, blogs, blogging, group, forum, military community,
search people, message, military photo, military image, love, dating,
sex, make love, friends, gun, fire, tank, air, navy seals, troop, kill,
war. 14
Reply to this comment
Share police stories and news
by lucifinil September 17, 2006 11:52 PM PDT
Share police stories and news

Check the news from police.vost.com

military friends, military networking military network, military
social, finding friends, blogs, blogging, group, forum, military community,
search people, message, military photo, military image, love, dating,
sex, make love, friends, gun, fire, tank, air, navy seals, troop, kill,
war. 39
Reply to this comment
bulky, crashy, trashy...
by aSiriusTHoTH September 18, 2006 8:55 AM PDT
I don't know about anyone else but for me FF has started to become bulky, crashy, and trashy. I can open up 4 - 5 tabs and easily see FF using over 150MB of ram and even higher. It will slow my computer down and eventually crash. This is across a network of 30+ computers.

Is it really time to start using Opera on our network?????
Reply to this comment
moron
by aSiriusTHoTH September 18, 2006 9:00 AM PDT
Stick to the story and get off the liberal/commie crap. I tend to lean to the left a bit and I don't like IE. Jumping to the politics right away, is just stupid.. its about FireFox.. not any moronic conclusions you have... get over it!
Reply to this comment
When's Auto-Update WITHOUT USER INPUT coming?
by gefitz September 18, 2006 1:44 PM PDT
When's Firefox going to come with functionality to automatically update Firefox WITHOUT USER INPUT? Am I missing that, or is it really not possible?

I'd love to get Firefox onto my corporate desktops, but trusting users to apply updates when they are available is simply NOT an option...
Reply to this comment
(15 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (-0.45%) -36.65 8,146.52
S&P 500 (-0.40%) -3.55 879.13
NASDAQ (0.20%) 3.48 1,756.03
CNET TECH (0.36%) 4.57 1,262.65
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right