The Register® — Biting the hand that feeds IT

Feeds

Firefox update plugs three critical flaws

Version 3.5.6 will patch your quilt

Agentless Backup is Not a Myth

Mozilla has pushed out a cross-platform update for Firefox that fixes multiple security flaws.

Firefox 3.5.6 lances three critical vulns in the open source browser software. They include memory problems involving the liboggplay media library, an integer overflow crash bug in the libtheora video library, and a separate memory corruption flaw. All three of the critical vulns create a possible mechanism for hackers to inject hostile code onto vulnerable systems, via drive-by download attacks or similar malign trickery.

The update, published on Tuesday, also tackles a variety of lesser vulnerabilities that (at worst) create a means to crash vulnerable systems. Firefox 3.5.6 also tackles stability bugs and tweaks features, as explained in Mozilla's release notes here.

Firefox 3.0.16 tackles similar flaws for users still using the 3.0.X version of the browser. 3.0.16 is needed to tackle one critical flaw in previous versions of the software, which compares to the three critical nasties lanced with 3.5.6.

As usual, Firefox bugs mean users of the corresponding version of Mozilla SeaMonkey application suite, version 2.0.1, also need to apply patches.

More ruminations on the possible consequence of leaving the flaws unfixed can be found a security advisory by Secunia here. ®

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Re: three MORE critical flaws

Well, keep in mind that these are flaws discovered before they have been exploited. With a closed sauce application you wouldn't know if there were any, would you?

Calling these flaws "critical" is IMHO misdirecting the general ignorant public, e.g. Andrew Norton. They are "critical" in the sense that they _could_ be used to subvert your system. Often closed sauce applications release fixes to "critical" flaws _after_ they have been exploited. And probably (but we can never know) they release fixes to "critical" flaws without even telling anyone.

To compare the security-ness of current browsers please look at how large a timeslice of their lifetime they are susceptible to actual exploited flaws. FF would still beat many (but not all) browsers hands down. Lynx FTW. :-)

7
0

Hype and Antihype

These comments make me laugh, Whenever a flaw is found in Firefox/Linux people jump all over it like flies on shit going 'Firefox/Linux is insecure crap! In your face fanbois!'

Yes, in your face fanbois, but these are found and fixed before they are exploited, whereas it takes a few botnets to appear before Microsoft will get off their arses to do anything about a flaw in their browser. (I exaggerate, for literary effect.)

When a flaw is found in these programs, because they have the marketing of being safe, when it's found they aren't perfect, people go mad. When will people realise that nothing is perfect? I mean, when did you last believe what the latest Microsoft Ad tells you?

Firefox is still > IE.

Case closed. (although likely to reopen if I can be arsed to argue the point.)

6
0

ogg & theora

The first vuln caused by HTML 5. FFS, browsers are to parse HTML and interpret JavaScript. Not fscking playing videos! If I want to play music or a video, I use one of the 5 software I have here to do this: QuickTime, Plex.app, Mplayer, VLC or heck, even iTunes! Not Firefox!

The guy that thought the browser should be the OS should be killed. Hence the grenade.

4
0

More from The Register

SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
Apple: iOS7 dayglo Barbie makeover is UNFINISHED - report
Plus: You don't like the icons? Blame marketing
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry