* [gentoo-user] Firefox 2.0.0.5
@ 2007-07-25 0:21 Stratos Psomadakis
2007-07-25 2:10 ` fire-eyes
0 siblings, 1 reply; 6+ messages in thread
From: Stratos Psomadakis @ 2007-07-25 0:21 UTC (permalink / raw
To: gentoo-user
i just did an update,and firefox 2.0.0.5 has been added to the tree(~
masked)...
but i just read a post at slashdot.org that says about a password
vulnerability of 2.0.0.5...
here's the link: http://it.slashdot.org/article.pl?sid=07/07/23/1450224
i just want to ask if it's ok to update to the new firefox,or if it's a
serious sec problem?... :/
thx...
--
gentoo-user@gentoo.org mailing list
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [gentoo-user] Firefox 2.0.0.5
2007-07-25 0:21 [gentoo-user] Firefox 2.0.0.5 Stratos Psomadakis
@ 2007-07-25 2:10 ` fire-eyes
2007-07-25 8:09 ` b.n.
2007-07-25 11:56 ` [gentoo-user] " Florian Philipp
0 siblings, 2 replies; 6+ messages in thread
From: fire-eyes @ 2007-07-25 2:10 UTC (permalink / raw
To: gentoo-user
Stratos Psomadakis wrote:
> i just did an update,and firefox 2.0.0.5 has been added to the tree(~
> masked)...
> but i just read a post at slashdot.org that says about a password
> vulnerability of 2.0.0.5...
> here's the link: http://it.slashdot.org/article.pl?sid=07/07/23/1450224
>
> i just want to ask if it's ok to update to the new firefox,or if it's a
> serious sec problem?... :/
>
> thx...
It's okay to update, as far as I know it's 2.0.0.5 and before (aka
everything...).
Your best bet is to not use the password saving features, install
noscript (important: WIPE OUT it's whitelist, then selectively add sites
you trust).
--
gentoo-user@gentoo.org mailing list
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [gentoo-user] Firefox 2.0.0.5
2007-07-25 2:10 ` fire-eyes
@ 2007-07-25 8:09 ` b.n.
2007-07-25 23:22 ` [gentoo-user] " »Q«
2007-07-25 11:56 ` [gentoo-user] " Florian Philipp
1 sibling, 1 reply; 6+ messages in thread
From: b.n. @ 2007-07-25 8:09 UTC (permalink / raw
To: gentoo-user
fire-eyes ha scritto:
>> i just want to ask if it's ok to update to the new firefox,or if it's
>> a serious sec problem?... :/
>>
>> thx...
>
> It's okay to update, as far as I know it's 2.0.0.5 and before (aka
> everything...).
>
> Your best bet is to not use the password saving features, install
> noscript (important: WIPE OUT it's whitelist, then selectively add sites
> you trust).
Has the bug been fixed upstream?
m.
--
gentoo-user@gentoo.org mailing list
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [gentoo-user] Firefox 2.0.0.5
2007-07-25 2:10 ` fire-eyes
2007-07-25 8:09 ` b.n.
@ 2007-07-25 11:56 ` Florian Philipp
1 sibling, 0 replies; 6+ messages in thread
From: Florian Philipp @ 2007-07-25 11:56 UTC (permalink / raw
To: gentoo-user
[-- Attachment #1: Type: text/plain, Size: 943 bytes --]
Am Mittwoch 25 Juli 2007 04:10 schrieb fire-eyes:
> Stratos Psomadakis wrote:
> > i just did an update,and firefox 2.0.0.5 has been added to the tree(~
> > masked)...
> > but i just read a post at slashdot.org that says about a password
> > vulnerability of 2.0.0.5...
> > here's the link: http://it.slashdot.org/article.pl?sid=07/07/23/1450224
> >
> > i just want to ask if it's ok to update to the new firefox,or if it's a
> > serious sec problem?... :/
> >
> > thx...
>
> It's okay to update, as far as I know it's 2.0.0.5 and before (aka
> everything...).
>
> Your best bet is to not use the password saving features, install
> noscript (important: WIPE OUT it's whitelist, then selectively add sites
> you trust).
There is an addon called "Secure Login". I think it solved the original
problem by preventing Firefox from sending paaswords without the users
agreement but I'm not sure if it really helps at all.
[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 6+ messages in thread
* [gentoo-user] Re: Firefox 2.0.0.5
2007-07-25 8:09 ` b.n.
@ 2007-07-25 23:22 ` »Q«
2007-07-26 0:04 ` Stratos Psomadakis
0 siblings, 1 reply; 6+ messages in thread
From: »Q« @ 2007-07-25 23:22 UTC (permalink / raw
To: gentoo-user
In <news:46A70555.3020502@gmail.com>,
"b.n." <brullonulla@gmail.com> wrote:
>fire-eyes ha scritto:
>>> i just want to ask if it's ok to update to the new firefox,or if
>>> it's a serious sec problem?... :/
>>>
>>> thx...
>>
>> It's okay to update, as far as I know it's 2.0.0.5 and before (aka
>> everything...).
>>
>> Your best bet is to not use the password saving features, install
>> noscript (important: WIPE OUT it's whitelist, then selectively add
>> sites you trust).
At least not use the password manager for sites that essentially let
users host pages on them, e.g. social networking sites.
>Has the bug been fixed upstream?
I don't know -- they restrict access to security-sensitive bug entries
until after an official release with a patch has been put out. It's
possible they won't fix this one at all; see the third and fourth
paragraphs at <http://www.heise-security.co.uk/news/93018>, and chase
links if you're really interested.
--
»Q«
--
gentoo-user@gentoo.org mailing list
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [gentoo-user] Re: Firefox 2.0.0.5
2007-07-25 23:22 ` [gentoo-user] " »Q«
@ 2007-07-26 0:04 ` Stratos Psomadakis
0 siblings, 0 replies; 6+ messages in thread
From: Stratos Psomadakis @ 2007-07-26 0:04 UTC (permalink / raw
To: gentoo-user
very interesting article...
hope that a solution will be found soon...
O/H »Q« έγραψε:
> In <news:46A70555.3020502@gmail.com>,
> "b.n." <brullonulla@gmail.com> wrote:
>
>
>> fire-eyes ha scritto:
>>
>>>> i just want to ask if it's ok to update to the new firefox,or if
>>>> it's a serious sec problem?... :/
>>>>
>>>> thx...
>>>>
>>> It's okay to update, as far as I know it's 2.0.0.5 and before (aka
>>> everything...).
>>>
>>> Your best bet is to not use the password saving features, install
>>> noscript (important: WIPE OUT it's whitelist, then selectively add
>>> sites you trust).
>>>
>
> At least not use the password manager for sites that essentially let
> users host pages on them, e.g. social networking sites.
>
>
>> Has the bug been fixed upstream?
>>
>
> I don't know -- they restrict access to security-sensitive bug entries
> until after an official release with a patch has been put out. It's
> possible they won't fix this one at all; see the third and fourth
> paragraphs at <http://www.heise-security.co.uk/news/93018>, and chase
> links if you're really interested.
>
>
--
gentoo-user@gentoo.org mailing list
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2007-07-26 0:07 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-07-25 0:21 [gentoo-user] Firefox 2.0.0.5 Stratos Psomadakis
2007-07-25 2:10 ` fire-eyes
2007-07-25 8:09 ` b.n.
2007-07-25 23:22 ` [gentoo-user] " »Q«
2007-07-26 0:04 ` Stratos Psomadakis
2007-07-25 11:56 ` [gentoo-user] " Florian Philipp
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox