LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-08-2005, 10:47 PM   #1
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
WARN: Firefox Vulnerabilities


Two significant vulnerabilities have been identified in the Mozilla Firefox browser affecting versions 1.0.3 (current) and earlier. A 0day exploit has also been released and confirmed to allow arbitrary code execution using a combination of both vulnerabilities. The vulnerabilities have been fixed in the nightly Firefox builds. Turning off the website software installation feature has been advised as a workaround until an update stable version is released. To disable software installation: (Edit-> Preferences -> Web Features -> uncheck "Allow websites to install software" -> OK).

See the following links for more info:
http://www.mozillazine.org/talkback.html?article=6582
http://secunia.com/advisories/15292/
 
Old 05-09-2005, 12:41 AM   #2
freakyg
Member
 
Registered: Apr 2005
Distribution: LFS 5.0 and 6.1
Posts: 705

Rep: Reputation: 30
thanks for the heads-up, personally I never let websites install software automagically...........it is the safest way to go these days.........
 
Old 05-09-2005, 01:54 AM   #3
DaneM
Member
 
Registered: Oct 2003
Location: Chico, CA, USA
Distribution: Linux Mint
Posts: 881

Rep: Reputation: 130Reputation: 130
Good call, Captain!

--Dane
 
Old 05-09-2005, 09:35 AM   #4
matrixcubed
LQ Newbie
 
Registered: May 2004
Location: Gatineau, QC
Distribution: Ubuntu 6.10
Posts: 25

Rep: Reputation: 15
I had twiddled with that, thinking it might be more secure, but then I wasn't able to install extensions. Weird.
 
Old 05-12-2005, 02:13 PM   #5
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
FYI, Fx 1.0.4 is now out.
 
Old 05-16-2005, 09:24 PM   #6
c0uchm0nster
Member
 
Registered: Nov 2003
Distribution: debian
Posts: 62

Rep: Reputation: 15
matrixcubed - to install extensions with website install turned off instead of clicking on the install link for the extension right-click and save the xpi to your computer, then click and drag it into the extensions window to start the install
 
Old 05-17-2005, 12:59 AM   #7
JrLz
Member
 
Registered: Mar 2004
Location: Jakarta
Posts: 164

Rep: Reputation: 30
yeah, check & try this one...... I tried with 1.0.2 windows and it worked......
Code:
http://www.mikx.de/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
WARN: Cyrus IMAP Vulnerabilities Capt_Caveman Linux - Security 0 11-26-2004 06:25 PM
IE Vulnerabilities, why not in other browsers? mandrakemikael Linux - Security 3 09-28-2004 11:43 AM
WARN: Kerberos Vulnerabilities Capt_Caveman Linux - Security 0 09-01-2004 08:53 PM
sendmail vulnerabilities odious1 Linux - Security 5 11-17-2003 09:06 AM
More BIND vulnerabilities jeremy Linux - Security 0 01-31-2001 08:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration