DesktopLinux
Home  |  News  |  Articles  |  Forum  |  Polls  |  Blogs  |  Videos  |  Resource Library

Keywords: Match:
Firefox, Thunderbird critical updates explained
Sep. 15, 2006

Mozilla on Sept. 14 reissued the popular open-source Firefox Web browser, and its email counterpart, Thunderbird, with new security and stability fixes. Each of the open-source apps rolls to version 1.5.0.7.

Firefox update

Firefox 1.5.0.7 comes with fixes for half-a-dozen minor security vulnerabilities. The first of these is a patch that will prevent possible attacks from opening a previously blocked popup that was using an XSS (cross-site scripting) attack.

Perhaps the most critical of these corrects an implementation error in the RSA security signature verification. This made it possible for an attacker to make a forged signature for an altered message.

Another serious problem that has been fixed was that JavaScript could be relatively easily tricked into heap buffer overflows. This, in turn, could be exploited to run a malware program.

The new browser version also prevents malicious sites from injecting content into a sub-frame of another site. This could have the effect of making an attackers' content look like it was part of the victim site.

Several other, less important security problems were also fixed. In addition, Firefox has been made more stable.

On Linux, Firefox now follows GTK widget library's setting for textbox keybindings. With these bindings, which are often called Emacs-bindings, pressing Ctrl+letters triggers application shortcuts instead of readline-like text-editing shortcuts.

The new Firefox will work flawlessly with most GTK/Gnome-based desktops, but there is one exception -- Fedora Core 3, because GNOME integration does not work properly.

Special Fedora Core 3 update process

Fedora Core 3 users must download and install linc-1.0.3-3.1.i386.rpm. Then, after installing it, they must run a shell, move the Firefox directory, and run the following command: touch .autoreg. After this, when Firefox is next run it should be properly integrated with GNOME.

Fedora Core 3 users will also need to follow the same procedure when they update to Thunderbird 1.5.0.7.

Thunderbird update

Speaking of Thunderbird, all but one of its security patches are identical to Firefox's fixes. The one exception is that even with JavaScript disabled in mail, an attacker can still execute JavaScript when a mail message is viewed, replied to, or forwarded by putting the script in a remote XBL (eXtensible Binding Language) file, which is then loaded by the message.

While this could happen despite JavaScript being disabled, a potential victim would have to have chosen to Load Images for the XBL/JavaScript trick to work. This attack would not be able to directly attack a system, but it could be used to change a message being viewed or enable an attacker to "spy" on the response to a message.

Patch availability

While there have been no reports of any of these patched holes being used in real-world exploits, Firefox and Thunderbird users should upgrade their programs as soon as possible. The Thunderbird patch can be found on the Mozilla Thunderbird website and the new Firefox can be downloaded from the Mozilla Firefox website.

Finally, there are also new security updates for the Mozilla-based Mac OS X Camino web browser and the SeaMonkey web browser/email Internet suite.


-- Steven J. Vaughan-Nichols




Related Stories:


(Click here for further information)


Approaching the Linux Desktop
The purpose of this paper is to help organizations evaluate the Linux desktop against their own enterprise needs and discover what benefits the Linux desktop might bring to their organizations.

Migrating To Linux: Application Challenges and Solutions
Several solutions exist to help organizations migrate in an orderly fashion from Windows to Linux desktops. This paper establishes the characteristics of an ideal cross-platform solution and reviews these alternatives in light of this ideal standard. The paper takes a closer look at the pros and cons of various solutions and outlines the business benefits that can be achieved.

Linux Advantages: Publicly Available Information on Linux Software
This paper offers a brief summary of readily-available Linux information to help businesses sort out this widely misunderstood operating system.

Top 5 Strategies for Managing Linux
Despite continuous evolution in the manageability of Linux, a 2006 survey cited manageability concerns as a top reason why organizations are hesitating to adopt Linux. Levanta believes Linux can be as manageable, if not more so, than other operating systems by following key strategies. These strategic recommendations were developed from experiences in numerous customer environments, both large and small.

Why Choose Novell for Linux?
This paper outlines the benefits of switching to the Linux platform and choosing Novell as a high-performance, enterprise solution.

Enterprise Linux Selection Guide
Considering moving your enterprise to the Linux operating system? Since there are so many similar versions, choosing the right one can be tough. This paper offers a clear process to help you make an informed decision and get the features, support, and cost that are right for your business and technical needs.

Overcoming Challenges in Managing Linux
Levanta has created a new administration model with innovative technology that breaks down the barriers to making the most of Linux systems. This paper will provide an in-depth look at the workings of Levanta’s product, the first Linux appliance of its kind.

SUSE Linux Enterprise 10 for Retail Businesses
Discover why major retailers have switched to SUSE Linux Enterprise Desktop in the back office. SUSE Linux Enterprise Desktop 10 is a low-cost desktop that offers a complete set of productivity applications and interoperates seamlessly with the other Windows, Macintosh and UNIX desktops in your store.

Moving to a Linux Desktop
Migrating from Windows to Linux on the desktop can be a substantial undertaking because it has the potential for touching -- and perhaps disrupting -- every user in your organization. Unlike a data center (server and infrastructure) migration that is largely transparent to users, the cultural and administrative transitions and environment readiness required to support a Linux desktop migration are extensive.

Seven Good Reasons to Exchange Exchange
This paper describes seven compelling reasons why you should switch from Exchange to Scalix.

 



Got a HOT tip?   please tell us!

ADVERTISEMENT
(Advertise here)

Resource Library


Popular recent stories:
• Linux an equal Flash player
• Linux, netbooks threaten Microsoft's fat profits
• gOS 3.0 goes gold
• Browser swallows OS
• Lenovo denies ditching Linux
• Lightweight, Linux-compatible browser evolves
• GNOME 2.24 gains "Empathy" IM
• Review: Pardus Linux
• Ubuntu to fund Linux development
• Ubuntu "Intrepid Ibex" available

All-time Classics:
• Choosing a desktop Linux distro
• Banshee -- the next best thing to Linux iTunes
• Running World of Warcraft on Ubuntu
• A simple Linux backup method
• The Best Free Desktop Linux . . . and how to make it better
• Linux-powered Asus Eee PC mini-laptop arrives
• The well-tempered Debian desktop
• Lenovo launches a netbook
• What's the best Linux for beginners?
• Getting to know Puppy Linux
• Xandros 4: The best desktop Linux for Windows users
• VirtualBox: The best virtualization program you've never heard of

Linux-Watch headlines:
• Amid controversy, Microsoft launches open source foundation
• As open source surges, Microsoft admits Linux threat
• Open source lobbying group emerges
• Open source Linux device drivers submitted by -- Microsoft?
• Google names Chrome OS partners
• Google's new OS marries Linux and Chrome
• Debian plans draw sharp warning from GNU guru
• OpenSource World announces keynote speakers
• Linux 2.6.30 gets new filesystems
• Intel to buy Wind River for $884 million


Join our Desktop Linux discussion forums:
•  Moving to Linux
•  Linux/Windows debate!
•  Linux Q&A
. . . and more
Visit the...


BREAKING NEWS

• Knoppix Live CD distro rev'd
• Debian Linux-based Google Chrome OS debuts, goes open source
• Mint 8 achieves RC1, and Fedora 12 goes final
• Dell PCs cram multimedia power into tiny package
• OpenSUSE 11.2 and Novell's Mono Tools ship
• ABI's Jeffrey Orr on rising Linux netbook sales
• Moblin v2.1 goes beta, adds 3G support
• Linux owns 32 percent of netbook market, says study
• Skype working on open source VoIP UI
• Ubuntu 9.10 final ships as IBM spins Ubuntu-based cloud distro
• CentOS rev's to version 5.4, tries on KVM
• Fedora 12 optimized for Atom-powered netbooks
• Puppy Linux 4.3 gains bugfix, rave reviews
• Hulu comes to Linux
• Reviews praise Ubuntu 9.10, knock Ubuntu Moblin Remix



Linux Netbooks


Linux smartphones!


news feed

Or, follow us on Twitter...


Home  |  News  |  Articles  |  Forum  |  Polls  |  About  |  Contact
 

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
Tech RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video | VARs | Channel News

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | Enterprise Network Security | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | Security IT Hub | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | igrep

Use of this site is governed by our Terms of Service and Privacy Policy. Except where otherwise specified, the contents of this site are copyright © 1999-2009 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise is prohibited. Linux is a registered trademark of Linus Torvalds. All other marks are the property of their respective owners.