First Vulnerability for Firefox 1.5

Discussion in 'Fred's House of Pancakes' started by Sufferin' Prius Envy, Dec 8, 2005.

  1. Sufferin' Prius Envy

    Sufferin' Prius Envy Platinum Member

    Joined:
    Jul 7, 2004
    3,998
    19
    0
    Location:
    USA
    Vehicle:
    Other Non-Hybrid
    Nothing to worry about, but Firefox may crash if you surf upon the exploit.

    The temporary work-around is to just clear history information when closing the browser . . . which is an easy three click operation in FF 1.5

    Tools > Clear Private Data > Clear Private Data Now (confirm which boxes you want selected prior to final click)
    .
    http://secunia.com/advisories/17934/
     
  2. galaxee

    galaxee mostly benevolent

    Joined:
    Mar 14, 2005
    9,810
    468
    0
    Location:
    MD
    Vehicle:
    2005 Prius
    thanks, SPE. :)
     
  3. brandon

    brandon Member

    Joined:
    Oct 24, 2004
    771
    9
    0
    Location:
    Manhattan, KS
    Vehicle:
    2005 Prius
  4. bookrats

    bookrats New Member

    Joined:
    Mar 12, 2004
    2,843
    2
    0
    Location:
    Seattle, WA
    As always, Patrick, thanks for watching out for us Firefoxers!
     
  5. NuShrike

    NuShrike Active Member

    Joined:
    Feb 21, 2005
    1,378
    7
    0
    Vehicle:
    2005 Prius
    Model:
    Five
    Firefox will not crash on startup, and as confirmed by the Mozilla Org which has been unable to confirm any crashes. This is more like a one-time mini-DoS.

    Mozilla Foundation, which released Firefox, said it was not able to confirm the browser would crash or be at risk of a DOS attack, after visiting certain Web sites. And Mozilla has not received any reports from users of such a problem, said Mike Schroepfer, vice president of engineering for Mozilla Corp.

    He added that Firefox 1.5 can be slugglish on its next start-up, due to a bug in the history.dat, but it is not a security problem.

    "We have gotten no independent verification that it crashes (Firefox), but there have been a lot of attempts to try," Schroepfer said.


    If the history.dat was filled, you just have to wait a minute or so, and Firefox will come up and act as normal for that session, and the next session.