public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] Firefox 2.0.0.5
@ 2007-07-25  0:21 Stratos Psomadakis
  2007-07-25  2:10 ` fire-eyes
  0 siblings, 1 reply; 6+ messages in thread
From: Stratos Psomadakis @ 2007-07-25  0:21 UTC (permalink / raw
  To: gentoo-user

i just did an update,and firefox 2.0.0.5 has been added to the tree(~ 
masked)...
but i just read a post at slashdot.org that says about a password 
vulnerability of 2.0.0.5...
here's the link: http://it.slashdot.org/article.pl?sid=07/07/23/1450224

i just want to ask if it's ok to update to the new firefox,or if it's a 
serious sec problem?... :/

thx...
-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [gentoo-user] Firefox 2.0.0.5
  2007-07-25  0:21 [gentoo-user] Firefox 2.0.0.5 Stratos Psomadakis
@ 2007-07-25  2:10 ` fire-eyes
  2007-07-25  8:09   ` b.n.
  2007-07-25 11:56   ` [gentoo-user] " Florian Philipp
  0 siblings, 2 replies; 6+ messages in thread
From: fire-eyes @ 2007-07-25  2:10 UTC (permalink / raw
  To: gentoo-user

Stratos Psomadakis wrote:
> i just did an update,and firefox 2.0.0.5 has been added to the tree(~ 
> masked)...
> but i just read a post at slashdot.org that says about a password 
> vulnerability of 2.0.0.5...
> here's the link: http://it.slashdot.org/article.pl?sid=07/07/23/1450224
> 
> i just want to ask if it's ok to update to the new firefox,or if it's a 
> serious sec problem?... :/
> 
> thx...

It's okay to update, as far as I know it's 2.0.0.5 and before (aka 
everything...).

Your best bet is to not use the password saving features, install 
noscript (important: WIPE OUT it's whitelist, then selectively add sites 
you trust).
-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [gentoo-user] Firefox 2.0.0.5
  2007-07-25  2:10 ` fire-eyes
@ 2007-07-25  8:09   ` b.n.
  2007-07-25 23:22     ` [gentoo-user] " »Q«
  2007-07-25 11:56   ` [gentoo-user] " Florian Philipp
  1 sibling, 1 reply; 6+ messages in thread
From: b.n. @ 2007-07-25  8:09 UTC (permalink / raw
  To: gentoo-user

fire-eyes ha scritto:
>> i just want to ask if it's ok to update to the new firefox,or if it's 
>> a serious sec problem?... :/
>>
>> thx...
> 
> It's okay to update, as far as I know it's 2.0.0.5 and before (aka 
> everything...).
> 
> Your best bet is to not use the password saving features, install 
> noscript (important: WIPE OUT it's whitelist, then selectively add sites 
> you trust).

Has the bug been fixed upstream?

m.
-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [gentoo-user] Firefox 2.0.0.5
  2007-07-25  2:10 ` fire-eyes
  2007-07-25  8:09   ` b.n.
@ 2007-07-25 11:56   ` Florian Philipp
  1 sibling, 0 replies; 6+ messages in thread
From: Florian Philipp @ 2007-07-25 11:56 UTC (permalink / raw
  To: gentoo-user

[-- Attachment #1: Type: text/plain, Size: 943 bytes --]

Am Mittwoch 25 Juli 2007 04:10 schrieb fire-eyes:
> Stratos Psomadakis wrote:
> > i just did an update,and firefox 2.0.0.5 has been added to the tree(~
> > masked)...
> > but i just read a post at slashdot.org that says about a password
> > vulnerability of 2.0.0.5...
> > here's the link: http://it.slashdot.org/article.pl?sid=07/07/23/1450224
> >
> > i just want to ask if it's ok to update to the new firefox,or if it's a
> > serious sec problem?... :/
> >
> > thx...
>
> It's okay to update, as far as I know it's 2.0.0.5 and before (aka
> everything...).
>
> Your best bet is to not use the password saving features, install
> noscript (important: WIPE OUT it's whitelist, then selectively add sites
> you trust).

There is an addon called "Secure Login". I think it solved the original 
problem by preventing Firefox from sending paaswords without the users 
agreement but I'm not sure if it really helps at all. 

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

* [gentoo-user]  Re: Firefox 2.0.0.5
  2007-07-25  8:09   ` b.n.
@ 2007-07-25 23:22     ` »Q«
  2007-07-26  0:04       ` Stratos Psomadakis
  0 siblings, 1 reply; 6+ messages in thread
From: »Q« @ 2007-07-25 23:22 UTC (permalink / raw
  To: gentoo-user

In <news:46A70555.3020502@gmail.com>,
"b.n." <brullonulla@gmail.com> wrote:

>fire-eyes ha scritto:
>>> i just want to ask if it's ok to update to the new firefox,or if
>>> it's a serious sec problem?... :/
>>>
>>> thx...
>> 
>> It's okay to update, as far as I know it's 2.0.0.5 and before (aka 
>> everything...).
>> 
>> Your best bet is to not use the password saving features, install 
>> noscript (important: WIPE OUT it's whitelist, then selectively add
>> sites you trust).

At least not use the password manager for sites that essentially let
users host pages on them, e.g. social networking sites.

>Has the bug been fixed upstream?

I don't know -- they restrict access to security-sensitive bug entries
until after an official release with a patch has been put out.  It's
possible they won't fix this one at all;  see the third and fourth
paragraphs at <http://www.heise-security.co.uk/news/93018>, and chase
links if you're really interested.

-- 
»Q«

-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [gentoo-user]  Re: Firefox 2.0.0.5
  2007-07-25 23:22     ` [gentoo-user] " »Q«
@ 2007-07-26  0:04       ` Stratos Psomadakis
  0 siblings, 0 replies; 6+ messages in thread
From: Stratos Psomadakis @ 2007-07-26  0:04 UTC (permalink / raw
  To: gentoo-user

very interesting article...
hope that a solution will be found soon...
O/H »Q« έγραψε:
> In <news:46A70555.3020502@gmail.com>,
> "b.n." <brullonulla@gmail.com> wrote:
>
>   
>> fire-eyes ha scritto:
>>     
>>>> i just want to ask if it's ok to update to the new firefox,or if
>>>> it's a serious sec problem?... :/
>>>>
>>>> thx...
>>>>         
>>> It's okay to update, as far as I know it's 2.0.0.5 and before (aka 
>>> everything...).
>>>
>>> Your best bet is to not use the password saving features, install 
>>> noscript (important: WIPE OUT it's whitelist, then selectively add
>>> sites you trust).
>>>       
>
> At least not use the password manager for sites that essentially let
> users host pages on them, e.g. social networking sites.
>
>   
>> Has the bug been fixed upstream?
>>     
>
> I don't know -- they restrict access to security-sensitive bug entries
> until after an official release with a patch has been put out.  It's
> possible they won't fix this one at all;  see the third and fourth
> paragraphs at <http://www.heise-security.co.uk/news/93018>, and chase
> links if you're really interested.
>
>   

-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2007-07-26  0:07 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-07-25  0:21 [gentoo-user] Firefox 2.0.0.5 Stratos Psomadakis
2007-07-25  2:10 ` fire-eyes
2007-07-25  8:09   ` b.n.
2007-07-25 23:22     ` [gentoo-user] " »Q«
2007-07-26  0:04       ` Stratos Psomadakis
2007-07-25 11:56   ` [gentoo-user] " Florian Philipp

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox