Author Topic: Latest Firefox update (2.0.0.13) causes crashes, possible hole  (Read 5090 times)

0 Members and 1 Guest are viewing this topic.

Offline Wretched Excess

  • Hero Member
  • *****
  • Posts: 15284
  • Reputation: +485/-84
  • Life, Liberty and the pursuit of Happy Hour
Latest Firefox update (2.0.0.13) causes crashes, possible hole

While there is no evidence of an exploit as of yet, Mozilla is taking a proactive measure to fix the issue before it could be.

A problem with stability which resulted in crashes and evidence of memory corruption was remedied in Firefox 2.0.0.13, however apparently the fix did not completely close any holes.

In fact, it seems as if it introduced new stability issues, where crashes occurred during JavaScript garbage collection. That feature allows a developer to reclaim the memory occupied by strings, objects, arrays, and functions that are no longer in use.

"We have no demonstration that this particular crash is exploitable but are issuing this advisory because some crashes of this type have been shown to be exploitable in the past," Mozilla said in an advisory.

Thunderbird is also affected, however JavaScript needs to be enabled. By default, this is not, and Mozilla said it discourages users from running scripts within mail.

JavaScript garbage collection problems have cropped up in the past. In February 2006, Mozilla addressed several issues within Firefox 1.5 which also posed a memory corruption and arbitrary code risks.

linky



heads up, FF users.  I stuck with 2.0.0.11, and do have periodic java issues.

Offline Wretched Excess

  • Hero Member
  • *****
  • Posts: 15284
  • Reputation: +485/-84
  • Life, Liberty and the pursuit of Happy Hour
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #1 on: April 17, 2008, 12:04:00 PM »

I no more posted that link than mozilla tried to push 2.0.0.14 to my desktop.  I'll d/l it later tonight.

the link to d/l 2.0.0.14 is here

Offline franksolich

  • Scourge of the Primitives
  • Global Moderator
  • Hero Member
  • *****
  • Posts: 58691
  • Reputation: +3066/-173
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #2 on: April 17, 2008, 12:26:24 PM »
Oh damn.

And it was just three hours ago that I downloaded an update on firefox.
apres moi, le deluge

Offline Wretched Excess

  • Hero Member
  • *****
  • Posts: 15284
  • Reputation: +485/-84
  • Life, Liberty and the pursuit of Happy Hour
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #3 on: April 17, 2008, 12:37:45 PM »
Oh damn.

And it was just three hours ago that I downloaded an update on firefox.

click on Help --> About Mozilla Firefox

you may have gotten the "fixed" update.

Offline franksolich

  • Scourge of the Primitives
  • Global Moderator
  • Hero Member
  • *****
  • Posts: 58691
  • Reputation: +3066/-173
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #4 on: April 17, 2008, 12:38:37 PM »
Okay, will do.

later: it says 2.0.0.14.

still later: I went to your link about deleting, but it doesn't show anything about deleting.
« Last Edit: April 17, 2008, 12:42:35 PM by franksolich »
apres moi, le deluge

Offline Wretched Excess

  • Hero Member
  • *****
  • Posts: 15284
  • Reputation: +485/-84
  • Life, Liberty and the pursuit of Happy Hour
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #5 on: April 17, 2008, 12:42:18 PM »
Okay, will do.

later: it says 2.0.0.14.


then you're cool, frank.  or as cool as mozilla can make you right now, anyway.  you must have gotten in just
under the wire. :wink:


Offline franksolich

  • Scourge of the Primitives
  • Global Moderator
  • Hero Member
  • *****
  • Posts: 58691
  • Reputation: +3066/-173
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #6 on: April 17, 2008, 12:43:28 PM »
Okay, will do.

later: it says 2.0.0.14.


then you're cool, frank.  or as cool as mozilla can make you right now, anyway.  you must have gotten in just
under the wire. :wink:



Okay, I'm back to being copacetic.  Thanks.
apres moi, le deluge

Offline Wretched Excess

  • Hero Member
  • *****
  • Posts: 15284
  • Reputation: +485/-84
  • Life, Liberty and the pursuit of Happy Hour
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #7 on: April 17, 2008, 12:46:25 PM »
Okay, will do.

later: it says 2.0.0.14.


then you're cool, frank.  or as cool as mozilla can make you right now, anyway.  you must have gotten in just
under the wire. :wink:



Okay, I'm back to being copacetic.  Thanks.

you were a copacetic guy before.  you were just a copacetic guy with a
potentially unstable browser. :-)

Offline Chris_

  • Little Lebowski Urban Achiever
  • Hero Member
  • *****
  • Posts: 46845
  • Reputation: +2028/-266
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #8 on: April 17, 2008, 02:32:10 PM »
I went straight to .14 also
If you want to worship an orange pile of garbage with a reckless disregard for everything, get on down to Arbys & try our loaded curly fries.

Offline Randy

  • Resident Grouch with a
  • Hero Member
  • *****
  • Posts: 4244
  • Reputation: +202/-39
  • Odd
Re: Latest Firefox update (2.0.0.13) causes crashes, possible hole
« Reply #9 on: April 20, 2008, 04:49:14 PM »
I guess running the No Script Add-On to Firefox stopped me having any problems?  :tinfoil: