• On MovieTome: Is this supposed to be Cobra Commander?
May 31, 2007 10:29 AM PDT

Mozilla issues security updates for Firefox 2 and 1.5

by Robert Vamosi

Mozilla has released Firefox 2.0.0.4 and Firefox 1.5.0.12 to address six security vulnerabilities. Most users will automatically receive this update and be asked to restart Firefox to install it. This update will probably be the final one for Firefox 1.5. As such, Mozilla provides an easy upgrade path for current 1.5 users to upgrade to 2.0. All Firefox users are urged to install this update, as it addresses the following security issues CVE-2007-2871 (XUL Popup Spoofing); CVE-2007-2870 (XSS using addEventListener); CVE-2007-1362 (Path Abuse in Cookies) CVE-2007-2869 (Persistent Autocomplete Denial of Service) CVE-2007-2867 and CVE-2007-2868 (Crashes with evidence of memory corruption).

This update also enhances Firefox support within the Windows Vista operating system, although links within some applications still may not open in Firefox even if you have chosen Firefox as your default browser; a Windows Media Player plug-in still doesn't exist for Firefox; Windows Vista Parental Controls are not completely honored yet within Firefox; and cookies and saved forms from Internet Explorer still have to be manually imported. Mozilla has posted workarounds for these.

Finally, this release of Firefox adds language support for Afrikaans and Belarusian.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
Add a Comment (Log in or register)
Firefox update (2.004)
by jennywren1420 June 4, 2007 7:47 AM PDT
This article implies that the update is only for Windows users, so that might be the reason that I didn't get an update message from Mozilla. Nevertheless, when I went to Mozilla's Firefox site, there was a prominent notice of a chance for OS X users to upgrade to version 2.004.

I use OS 10.4.9 (Tiger), and my current Firefox is version 2.003. Any suggestions for how to find out just who should be updating Firefox? Only Vista users?as implied in the Security article? If not, which Mac users need this, too? The item for download at Mozilla didn't show any specs.

Thanks, folks.
Reply to this comment
Update is for all platforms
by pcabellor June 4, 2007 6:54 PM PDT
jenny, the update is for all platforms. Since it includes fixes for five security vulnerabilities one labeled as critical, you for sure should update as soon as possible. For more details check: http://mozillalinks.org/wp/2007/05/firefox-200415012-updates-are-out/
advertisement

Can RIM get its mojo back?

The new BlackBerry Tour, carried by Verizon and Sprint, arrives Sunday, even as RIM seems to be losing sales to exclusive devices like the iPhone and Pre.

With Chrome, Google reignites the OS wars

roundup Google Chrome OS, due in 2010, underscores the Web giant's cloud-computing ambitions and opens new competition with Microsoft.
• What Chrome OS has on Windows that Linux doesn't

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right