Firefox 3.0.1 Fixes 'Carpet Bombing' Issue
An anonymous reader writes "Firefox 3.0.1 was released today. It fixes 3 security vulnerabilities, including a critical issue reported by Billy Rios, Ben Turner, and Dan Veditz. The issue could be combined with an issue in Apple's Safari browser to read data from the user's disk or to execute arbitrary code. This issue was previously discussed on Slashdot.
The release also fixes a remote code execution bug involving the CSS reference counter, reported by the Zero-Day Initiative (previously discussed on Slashdot here), as well as a Mac-only potential code execution bug involving GIF image rendering, reported by Drew Yao of Apple Product Security."
Seriously. It's a .1 release. No one cares when Opera or Safari have a similar release.
So how about we set a download record for patches. oh wait we don't want to reset the clock for the multiple server failures like the original release.
Firefox 3 was crashing 3-10 times a day for me even after completely removing everything FF related. At the risk of jinxing myself I will say that I'm crash free on 3.0.1 for 4 hours now.
return EXIT_SUCCESS;
This update disabled my Firebug and "Copy all Urls" extensions.
I'll never take an update on the first day again. Ever. *spit*
Really, hopefully we'll stop hearing about this stupid 'vulnerability' and its 2,000 slashdot stories.
... I didn't download Firefox 3 when it came out. In fact, I'm still on Firefox 2, and I'm sure a good percentage of fellow /.ers are as well.
Remember: if there aren't any patches for it, chances are that the reason is not that it's bug-free, but that it's still buggy.
Tomato wedge sperm darts that are Republican.
So have they given us the option to disable their "awesome bar" yet?
I had to giggle at the workaround. To prevent a firefox flaw from biting you, you need to have firefox open. Phew, I'm so glad I'm safe.
Don't anthropomorphize computers. They *hate* that.
So far as I know, the only application that normally runs with its current directory on the desktop (and is thus a potential target for any successful exploit of this issue) is Internet Explorer.
This attack only works if the user is using another internet-connected application with Firefox not running. Using Firefox, or making sure it is at least running, prevents this attack.
So as long as you use Firefox all day long, you will not be affected.
As I was reading this post, the update was auto-downloading.
Slashdot needs a "important software updates" section.
(released the day before yesterday)
http://www.mozilla.org/security/known-vulnerabilities/firefox20.html
Fixed in Firefox 2.0.0.16
MFSA 2008-35 Command-line URLs launch multiple tabs when Firefox not running
MFSA 2008-34 Remote code execution by overflowing CSS reference counter
(released yesterday)
http://www.mozilla.org/security/known-vulnerabilities/firefox30.html
Fixed in Firefox 3.0.1
MFSA 2008-36 Crash with malformed GIF file on Mac OS X
MFSA 2008-35 Command-line URLs launch multiple tabs when Firefox not running
MFSA 2008-34 Remote code execution by overflowing CSS reference counter
Whew! Good thing you didn't upgrade! You might have been vulnerable for a whole extra day! (Wait, you did take the 2.0.0.16 update already, right?)
Clever name troll twitter.
We should have a new mod option, -1 twitter
For anyone on a slow connection or with an old machine (like me) that was almost a showstopper. Thankfully, *seems* to be fixed now.Haven't seen any real crashes to the desktop even with the betas...
A workaround is to go Tools->Options-> Security and turn off the attack site and forgery options.
Andy
Now if only they could get around to fixing the much bigger memory issues that seem to get worse and worse with every release. I'm getting tempted to go back to IE for the first time in years.
I've been using the Firefox 3 nightly builds since they introduced the new theming (the Mac version started looking decent at that point). In all that time--remember, this is a nightly build--I've had about three crashes. I've had no crashes since installing Firefox 3.
What's that supposed to mean? We're not talking about a whole new project here, or a brand-new operating system--Firefox 3 is a bunch of patches over Firefox 2. Give it a chance.
http://dictionary.reference.com/search?q=irony
Patrick Doyle
I mod down every jackass who puts his moderation policy in his sig. Oh, wait a sec....
I could swear that I was notified of a security update regarding Firefox a few days ago. After the update, I checked Firefox and it's own About dialog reported it was 3.0.1. Can anyone else confirm this or am I going bonkers? I'm certainly on 3.0.1 now and I only received some mundane updates this morning.
Stop being such a dick twitter.
Okay, just downloaded the version 3.0.1. What do I see now? My Google toolbar is gone, adblock not working, all other add-ons seem to be dead. Any idea when will the add-ons be updated?
The other day I had about 180 tabs open (cleaning up my del.icio.us) and memory usage was about 600MB. That's a whole three megabytes per tab! What's wrong with these people?! :)
Slashdot needs a "important software updates" section.
I thought it was called "Freshmeat".
I expect Slashdot to either have news of events before they go live or after a 7-day delay, depending on the phase of the moon and CowboyNeal's health.
I never expect it to be "right on time."
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
Back in my day we had to squeeze all our tabs in 640KB!
And there were only 5 computers on the whole planet!
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
The update for FF2 was pushed out a day before the FF3 update (on Tuesday morning, versus Wednesday afternoon). If you aren't using 2.0.0.16, you're prone to the same attack.
Usually when people say "ironic" I assume they're using it incorrectly, and I think this is the first time I've been wrong. :-)
Patrick Doyle
I mod down every jackass who puts his moderation policy in his sig. Oh, wait a sec....
Who would want to bomb a carpet company?
Except for on Windows 98... I didn't even know Mozilla had a carpet bombing issue. My only issue with Mozilla is the fact that it just randomly crashes out of nowhere. For no reason that I can think of. Not often, but it happens. I'm on Vista, I expect everything to crash! :((
Even The Sims 2 crashes unexpectedly, along with every other game I own. Stupid Dell. Stupid Ranting. Stupid Vista! STUPID ME! :(
Sorry, getting off topic ^_^
if it's just the appearance changes (i.e., SSL sites not shown in yellow, big layout) you can use "old location bar", but you might also look at changing your theme: "classic compact" looks pretty much as Firefox 2 did, and it saves a lot of vertical space too. (Nice on laptops.) I use it, and install it on all my customer's machines. Instructions below, to prevent pop-up of matches, are excellent.
The appearance doesn't really bother me. It's the matching algorithm. Typing in "ca" should match carrionfields.com, but it shouldn't match chewbac.ca in my opinion.
By what name do you wish to be mourned?
Whenever Firefox is mentioned on slashdot, make sure to bring up the memory leak issue .. :)
davecb5620@gmail.com
http://slashdot.org/moderation.shtml go learn something. damn fool kids...
For those who can't memorize every URL, the awesome bar works perfectly!
Typing in "cnet" shows the *.cnet.* you visited. You don't have to remember to prefix it with www./asia./news. first to get the correct selection ... and typing "cnet eee" will show you that review you wanted to read again (cnet is part of the URL, eee is part of the title, works like tagging).
And if you type "co", like your example, and select the "compiz.org" page you actually wanted and ignore every .com it also highlights, it will give compiz prio over .com the next time and put it first.
Install cygwin to get full chmod support, even on XP Home...
Now fix the Awesome Bar so that I can revert back to the way address bars should work!
"He who can destroy a thing, controls a thing." --Paul Atreides, Dune
eventually that should change.
I used to type just "ma" to get mail.myemployersdomain.com, but it was bringing up slashdot ("Slashdot: News for nerds, stuff that matters"). eventually, after typing "mail" for long enough, now mail.myemployersdomain.com is the first thing that comes up when I just type "ma".
It's sad, but in the last couple of months a lot of trolls and flamers are screwing with /. topics. If you don't have nothing good to say or want to be the first to post, please keep it for yourself and don't mess with the thing.
[]Âs
Am I eval()? - http://www.monst3r.com.br
http://developer.yahoo.net/blog/archives/2007/07/yahoo-hadoop.html
Besides, Google's search engine doesn't run on MapReduce - they use MapReduce to build the indexes. The key with Google is the GFS...
Truecrypt + portable Firefox = pr0n hidden
-
Is not subject to the "my blank is cooler and better than your blank" ethos.
Slashdot, of course, must be contrarian on this point. "My blank is the best of all possible blanks, and you can blank off if you don't blanking think so."
Tell me, do you want to spend the rest of your life window shopping for the awsumest browser or do you just want to pick one that doesn't splash buttcrack juice all over your hard drive and use the bloody thing?
You know, that question I just asked seems rhetorical, but /. rules of etiquette demand a response.
Well it's too late for the Afghanis and the Iraqis, but I'm sure the Iranians are relieved that there is a patch to stop them getting carpet bombed.
What if Tetris was invented by Nazis?
3.0.1 resolves the problem of "[Firefox3] suffers from garbage collection hick up" in Defender of the favicon
Now I can get back to gaming in the corner of my address bar.
Let me save you some time and map out your journey to acceptance of the awesome bar.
First you hate it, because it's new and different to what you expect. You are trained to use it as an address bar and nothing else, so it acting like a search bar is confusing and suboptimal to you.
At this point many people decide to trial the new bar, but you are the kind of person who tends to think he (forgive me, but he) knows what's good and what's not, and even quite enjoy the idea of customizing your Firefox. So you look for a way to preserve your old behavior. There are enough people like you to make worthwhile a mass solution: a config option and an extension.
You and your anti-awesome fellows make use of these. You occasionally grumble that the awesome bar shouldn't be default at all, but you are basically satisfied so the rest of the world hears from you less and less.
As time passes, you occasionally find yourself using other people's computers that have Firefox in a default state. This annoys you at first and if you are spending any serious time on them, you disable the awesome bar. But sometimes you're only using them briefly, so it's not worth modifying. Then, all of a sudden, you find the awesome bar useful. It's a surprise, like a door opening: you suddenly see that if you alter your behavior a little, the awesome bar could be quite useful.
From this point you never disable the awesome bar again, although you leave it disabled on your main desktop, as a matter of principle.
A new version of Firefox is released. The "Disable Firefox Awesome Bar" extension hasn't yet been updated to work on it. But by now you don't really mind. You now prefer the awesome bar. When you have to use Internet Explorer, or Firefox 2, the lack of an awesome bar bugs you. It seems so inflexible, so archaic.
A while later, the author of the awesome-disabling extension stops updating it. People forget that anybody ever didn't like the awesome bar. But this new Firefox feature, the predictive URL form mapping--oh man, that's just so horrible, why is it on by default?
I should buy some cement.
And if you have been paying attention, a good majority of the posts are "funny". Even the ones moderated otherwise.
Do some research, moron. DSRM.
And if you haven't caught on by now, (and obviously you haven't) my first post was a comment on the article itself. Who picks these anyway? Regardless, get a SOH. Or go post somewhere els.
You can only be young once. But you can always be immature.
proof* Posted by CmdrTaco on Thursday July 17, @12:29PM The update was Today,July17 For Europe time @20:50mm ,and im working at my comp from 19:00mm..whats rong?
is not 1 or 2 hours its a hole day!