Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Firefox security problem affects OS X, Windows, Linux
TGDaily ^ | Friday, August 14, 2009 08:36 | TG Daily Staff

Posted on 08/17/2009 2:49:23 AM PDT by Swordmaker

A site claims that there is a "fundamental problem" with Firefox updates using the OS X operating system.

Linux and Windows operating systems are affected too.

Paul Sture says that if you run as a non-admin user on OS X, Firefox grays out the check for updates menu item and doesn't automatically tell you when security updates are available.

Firefox, he says, only allows Update Checking when you have write access to the Firefox application although most people do their daily work on a non-privileged account.

He says he's pointed out the flaw to the Secure IT Foundation.

There's more details here .


TOPICS: Computers/Internet
KEYWORDS: firefox; macfud
Navigation: use the links below to view more comments.
first previous 1-2021-27 last
To: Swordmaker

Also, I don’t see any mention of versions or if Firefox was installed under Admin rights or user rights.


21 posted on 08/17/2009 9:54:29 AM PDT by papasmurf (RnVjayB5b3UsIDBiYW1hLCB5b3UgcGllY2Ugb2Ygc2hpdCBjb3dhcmQh)
[ Post Reply | Private Reply | To 1 | View Replies]

To: palmer

Firefox updates for Ubuntu come through the update manager, which comes from Canonical. If you check your auto-updates through “about:config”, what does it show there? Mine shows True, but the updates always come from the update manager.


22 posted on 08/17/2009 10:01:14 AM PDT by papasmurf (RnVjayB5b3UsIDBiYW1hLCB5b3UgcGllY2Ugb2Ygc2hpdCBjb3dhcmQh)
[ Post Reply | Private Reply | To 6 | View Replies]

To: shorty_harris

Try this.

Open a browser window and type “about:config” (without the quotes) and click I’ll be careful, I promise!

The type in the address bar there, “app.update.enabled” (without the quotes), and look to the right. That will tell you if the USER can receive the update or not. (double click the line to change the Value)


23 posted on 08/17/2009 10:10:03 AM PDT by papasmurf (RnVjayB5b3UsIDBiYW1hLCB5b3UgcGllY2Ugb2Ygc2hpdCBjb3dhcmQh)
[ Post Reply | Private Reply | To 12 | View Replies]

To: papasmurf

Mine showed true too, just set it to false, but it didn’t change the grayed out box. Also tried setting update.mode to zero, same thing, no effect on the grayed out checkbox.


24 posted on 08/17/2009 10:42:26 AM PDT by palmer (Cooperating with Obama = helping him extend the depression and implement socialism.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: papasmurf
"app.update.enabled"

Ah, that did the trick. Set that to false, auto-updates checkbox is turned off now (still grayed out). Now I can relax (I hate auto-update).

25 posted on 08/17/2009 10:45:00 AM PDT by palmer (Cooperating with Obama = helping him extend the depression and implement socialism.)
[ Post Reply | Private Reply | To 23 | View Replies]

To: palmer

If was already greyed out, it won’t change it.

It’s NOT greyed out by default on installation. BUT, if you click it, it WILL grey out, and stay that way. LOL

That’s on FF 3.0.13 on Ubuntu 9.04, which started out as hardy, and upgraded every 6 months.

I just checked my Puppy box, it has SeaMonkey and FF (BonEcho). SeaMonkey and FF both list update notifier=True, and the souce as SeaMonkey Project and PuppyOrg, respectively.

I think somneone had a bad hair day, maybe they found a Gray hair???


26 posted on 08/17/2009 10:59:19 AM PDT by papasmurf (RnVjayB5b3UsIDBiYW1hLCB5b3UgcGllY2Ugb2Ygc2hpdCBjb3dhcmQh)
[ Post Reply | Private Reply | To 24 | View Replies]

To: kevkrom
And, may I add, the idea that a non-admin user should be able to modify a software package on a multi-user operating system is patently crazy. Sometimes there's a darn good reason for deferring software upgrades, even security updates, and non-admin users shouldn't have the ability to override admin decisions like that.

You are exactly correct. If you have a multi-user system, you still have to be an administrator to that system. So login once in a while as admin and take care to things.

27 posted on 08/17/2009 11:11:23 AM PDT by stripes1776 ("That if gold rust, what shall iron do?" --Chaucer)
[ Post Reply | Private Reply | To 7 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-27 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson