LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 03-24-2010, 07:03 PM   #1
Maestro485
Member
 
Registered: Apr 2004
Location: Pittsburgh
Distribution: Slackware
Posts: 136

Rep: Reputation: 16
Slackware 13 and the recent Firefox vulnerability


As you might have heard, a recent critical vulnerability was discovered in Firefox 3.6.

Any word on a Slackware patch coming soon?

I'd prefer to use a Slackware package rather than the actual Mozilla release, but I also don't like browsing the web with a remote code execution bug in my browser.

Or is Slackware unaffected by this? Please correct me if I'm wrong.

Thanks,
Matt
 
Old 03-24-2010, 08:01 PM   #2
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: SlackwareŽ
Posts: 13,925
Blog Entries: 44

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Hi,

There is a security fix for Slackware 12.2 but that was for FF 3.05.

Quote:
Here are the details from the Slackware 12.2 ChangeLog:
+--------------------------+
Sat Mar 6 18:57:32 UTC 2010
patches/packages/mozilla-firefox-3.0.18-i686-1.tgz: Upgraded.
Upgraded to firefox-3.0.18.
This fixes some security issues.
For more information, see:
http://www.mozilla.org/security/know...firefox30.html
(* Security fix *)
+--------------------------+

You can look at ;http://www.mozilla.org/security/know...firefox36.html

I'm not aware of a FF security fix for 13 or -current.


EDIT: I don't see a 'remote code execution bug' at http://www.mozilla.org/security/know...firefox36.html

EDIT2: WOFF heap corruption due to integer overflow is the bug the OP is speaking of.

Last edited by onebuck; 03-24-2010 at 08:23 PM.
 
1 members found this post helpful.
Old 03-24-2010, 08:12 PM   #3
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,897

Rep: Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019
It's this one Gary:

http://www.mozilla.org/security/anno...sa2010-08.html

And yes, it's quite nasty and has been out there for about a month.

The bug is in the parser for downloadable fonts, so I believe that going into about:config and changing gfx.downloadable_fonts.enable to false will help mitigate the risk until the team have had time to put a new package together.

I downloaded the sources and built my own 3.6.2 package yesterday as I didn't want to wait.

Last edited by GazL; 03-24-2010 at 08:16 PM.
 
1 members found this post helpful.
Old 03-24-2010, 08:19 PM   #4
onebuck
Moderator
 
Registered: Jan 2005
Location: Central Florida 20 minutes from Disney World
Distribution: SlackwareŽ
Posts: 13,925
Blog Entries: 44

Rep: Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159Reputation: 3159
Hi,

Thanks!

I wasn't aware of it. I just looked at the changelogs but did not notice a problem.

Again thanks for the link, heads up and temporary fix.

 
Old 03-24-2010, 08:32 PM   #5
Maestro485
Member
 
Registered: Apr 2004
Location: Pittsburgh
Distribution: Slackware
Posts: 136

Original Poster
Rep: Reputation: 16
Thanks a lot for the suggestions! Hopefully they can get a patch out soon.
 
Old 03-24-2010, 11:09 PM   #6
MannyNix
Member
 
Registered: Dec 2005
Location: ~
Distribution: Slackware -current
Posts: 465

Rep: Reputation: 53
Quote:
Originally Posted by GazL View Post
I downloaded the sources and built my own 3.6.2 package yesterday as I didn't want to wait.
This type of freedom and simplicity is why I like Slackware so much.
 
Old 03-25-2010, 12:14 AM   #7
slowpoke
Member
 
Registered: Feb 2010
Posts: 33

Rep: Reputation: 15
Where would I find a Slackbuild for FireFox?
 
Old 03-25-2010, 12:21 AM   #8
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,263
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
Quote:
Originally Posted by slowpoke View Post
Where would I find a Slackbuild for FireFox?
source/xap/mozilla-firefox/mozilla-firefox.SlackBuild
 
Old 03-25-2010, 12:27 AM   #9
slowpoke
Member
 
Registered: Feb 2010
Posts: 33

Rep: Reputation: 15
Thanks!
 
Old 03-25-2010, 12:34 AM   #10
MannyNix
Member
 
Registered: Dec 2005
Location: ~
Distribution: Slackware -current
Posts: 465

Rep: Reputation: 53
Quote:
Originally Posted by slowpoke View Post
Where would I find a Slackbuild for FireFox?
On almost any Slackware mirror on the /source/xap/mozilla-firefox/ dir

Depending on your Slackware version, here's a starting point

(Your mileage may vary, I'm running -current and it runs great, but it's up to you make sure it will work with the version you're running. You should have at least a minimal understanding of the way a Slackbuild works. Sbo is a different proyect (No support for this particular unofficial customization) but their How-To may help getting started using slackbuilds.
Good luck!
 
Old 03-25-2010, 08:56 AM   #11
slowpoke
Member
 
Registered: Feb 2010
Posts: 33

Rep: Reputation: 15
Found it.
Thanks!
 
Old 03-31-2010, 06:39 AM   #12
mutexe
Member
 
Registered: May 2009
Location: Malvern, UK
Distribution: Slackware 14.1
Posts: 240

Rep: Reputation: 32
Sorry to hijack thread, but:
Code:
ARCH=${ARCH:-i686}
Does this mean the slackbuild wont work on my 32 bit machine? Could i just change the numbers? Also, do slackbuilds effectively do the compiling and installing for you? I wanna have go at compiling something, just a bit nervous.

Once again sorry for the hijack, but i am trying to get FF 3.6.2 and this seems like a very relevant thread.

Cheers,
Tom
 
Old 03-31-2010, 06:44 AM   #13
brianL
LQ 5k Club
 
Registered: Jan 2006
Location: Oldham, Lancs, England
Distribution: Slackware64 15; SlackwareARM-current (aarch64); Debian 12
Posts: 8,298
Blog Entries: 61

Rep: Reputation: Disabled
It should work. What processor have you got? Post the results of uname -a.
 
Old 03-31-2010, 06:57 AM   #14
mutexe
Member
 
Registered: May 2009
Location: Malvern, UK
Distribution: Slackware 14.1
Posts: 240

Rep: Reputation: 32
Super fast reply. Cheers, i'll post output when i get home from work tonight!

Thanks again,
Tom
 
Old 03-31-2010, 11:49 AM   #15
Lufbery
Senior Member
 
Registered: Aug 2006
Location: Harrisburg, PA
Distribution: Slackware 64 14.2
Posts: 1,180
Blog Entries: 29

Rep: Reputation: 135Reputation: 135
Hi all,

While it is possible (and frankly easy) to roll my own updated Firefox using a new source file and the SlackBuild script in the sources, it would be nice to have an official update.

Has anyone had any word?

Regards,
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Mozilla confirms critical vulnerability in Firefox 3.5 LXer Syndicated Linux News 0 07-15-2009 06:00 PM
LXer: Password vulnerability in Firefox 2.0.0.5 LXer Syndicated Linux News 2 07-23-2007 04:41 PM
Vulnerability in Firefox 1.0.4 / Mozilla 1.7.8 win32sux Linux - Security 24 09-09-2005 04:23 PM
Firefox/Javascript security vulnerability...... BajaNick General 2 04-12-2005 09:22 AM
downloading fix for recent security vulnerability - RH v2.1 AS joeslazenger Linux - Security 1 12-03-2003 02:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 09:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration