Flurry of Security Patches
yggy writes "It's been a hectic day on the security patching front. Microsoft's bulletins for July include patches for three critical vulnerabilities on the same day that Mozilla releases new security updates for Firefox and Thunderbird. Not to be left behind, Apple fixed two Tiger flaws while Oracle issued a critical database server update." (See these separate stories on today's release of Firefox 1.0.5 and the 10.4.2 update from Apple, too.)
...the zlib bug
Here's some good info that colfer from this MozillaZine thread dug up:
3 0
1 0
7 7
3 2
6 4
3 6
3 1 .ico file
1 8
0 6
5 2
7 0
1 3
7 8
1.0.5 is mainly a security fix, but I have seen a bunch of non-security fixes creep in also, such as removing the default checkbox "yes" for "make firefox my home page." This looks like a big cleanup for the 1.0.x branch, before 1.1 takes over.
I don't know about the security fixes, besides the medium-risk frame/window spoofing thing (with 1.0.4, you should not open untrusted sites at the same time as sensitive sites...). Here are the non-security fixes (non-security as it seems to me) checked in since 1.0.4:
https://bugzilla.mozilla.org/show_bug.cgi?id=2837
"Save As" dialog tries to overwrite link/shortcut (.lnk) file instead of opening the directory/folder
https://bugzilla.mozilla.org/show_bug.cgi?id=2952
Tab title different from window title on initial load at gmail
https://bugzilla.mozilla.org/show_bug.cgi?id=2837
Right arrow key after selecting autocomplete result no longer uses selected item
https://bugzilla.mozilla.org/show_bug.cgi?id=2912
update installer packages should offer unchecked check box for setting start page
https://bugzilla.mozilla.org/show_bug.cgi?id=2910
Helper app dialog incomplete for non-nsStandardURL types
https://bugzilla.mozilla.org/show_bug.cgi?id=2655
(64-bit only issue)
https://bugzilla.mozilla.org/show_bug.cgi?id=2456
Crash loading (particular)
https://bugzilla.mozilla.org/show_bug.cgi?id=1418
Table with large rowspans and colspans hangs the browser
https://bugzilla.mozilla.org/show_bug.cgi?id=2880
Drag image across browser windows --> crash
https://bugzilla.mozilla.org/show_bug.cgi?id=2950
Obscure Javascript crash
https://bugzilla.mozilla.org/show_bug.cgi?id=2962
Default user agent problem (AIX platform only)
https://bugzilla.mozilla.org/show_bug.cgi?id=2808
Crash on OS/2 platform
https://bugzilla.mozilla.org/show_bug.cgi?id=2937
bookmarks toolbar missing in 2nd opened window, links in second window possibly cause crash
Among the other fixes, Firefox 1.0.5 contains a patch to CAPS (Configurable Access Policies) that finally eliminates crashes reported by users of the NoScript extension. This should make Firefox users even more safe: its "whitelist based pre-emptive script blocking approach prevents exploitation of security vulnerabilities (known and even not known yet!) with no loss of functionality"...
It only passes if you use a nightly. A shipped release has never passed the acid 2 test.
save the GNUs!