Firefox 3.5's First Vulnerability "Self-Inflicted"
CWmike writes "Mozilla has confirmed the first security vulnerability in Firefox 3.5, saying that the bug could be used to hijack a machine running the company's newest browser. A noted Firefox contributor called the situation 'self-inflicted' and said it was likely that the hacker who posted public exploit code Monday became aware of the flaw by rooting through Bugzilla, Mozilla's bug- and change-tracking database. The vulnerability is in the TraceMonkey JavaScript engine that debuted with Firefox 3.5, said Mozilla. '[It] can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code,' Mozilla's security blog reported Tuesday."
You mean that you actually want example exploit code to be available to everyone? Why?
What a fool believes, he sees, no wise man has the power to reason away.
So when they know about and are actively working on fixing a bug that is an exploit vulnerability, you think they should do it in public?
I get the argument that telling your users about it means that they can protect themselves (say, by running noscript), but for a consumer facing organization like Mozilla, the majority of users aren't going to notice or do anything.
Nerd rage is the funniest rage.
Mod Parent Up "this should have been in the summary, Taco".
Geezus....I should probably stop reading this site, it seems that everyone is so sure of themselves and are ALWAYS in the right that you actually have time to quabble over insignificant details. yeah he may have been incorrect (doubtful!) but do really think that the point was lost to anyone that read it? or caused ANY confusion? Why bother then?
get over yourselves, we aren't all born perfect, and may make mistakes. There is absolutely no reason to jump all over somebody for such a piddly mistake, EXCEPT TO BOOST YOUR OWN EGO!
rant off....
But, the majority of users only update firefox when it pops up a "hey, there's an update. Click here!" prompt.
The issue is unfixed for 90% of users until that occurs.