Skip to comments.
Mozilla Says Firefox 1.5 Bug Not Serious
TechWeb News ^
| December 12, 2005
| Greg Keizer
Posted on 12/12/2005 10:15:30 AM PST by Eagle9
Mozilla Corp. has warned users of its newest browser, Firefox 1.5, that a bug in how the software handles extremely long names can make it seem that the computer has crashed. The flaw, however, does not expose users to attack, contrary to earlier reports by researchers.
Malicious pages with very long titles--the proof of concept for the pseudo denial-of-service (DoS) attack contained 2.5 million characters--make the browser appear to hang, said Mozilla in an online security advisory, although the software is actually busy processing the name. Once encountered, the very slow start can't be corrected until the site name is removed from Firefox's history file.
Last week, researchers of the PacketStorm security group claimed that the bug could result in not just a DoS, but a more serious buffer overflow, which could be used in turn by attackers to compromise the system.
Mozilla, however, said that additional investigations showed that there is no danger of a buffer overflow. "We can find no basis for claims that variants of this denial-of-service attack can cause an exploitable crash," stated the Mozilla advisory. "There does not appear to be any risk to users or their computers beyond the temporary unresponsiveness at startup."
The advisory also includes instructions on clearing the history file of the too-long site name.
Mozilla has not set a release date for a fix.
TOPICS: Technical
KEYWORDS: browser; firefox; mozilla
Navigation: use the links below to view more comments.
first previous 1-20, 21-29 last
To: Hank Rearden; All
I don't have an answer, but the fact you say you have a lot of bookmarks leads me to ask if you do or how you back your stuff up. If you don't have this, get it, since it's free:
http://mozbackup.jasnapaka.com/
It works with FF and the Mozilla suite and T-bird.
One of my biggest gripes is how FF has had a bookmark problem for who knows how long, and they've yet to address it.
21
posted on
12/12/2005 5:24:04 PM PST
by
JoJo Gunn
(Help control the Leftist population. Have them spayed or neutered. ©)
To: George from New England; M0sby; Hank Rearden; tubebender; JerseyHighlander; Big Giant Head; All
I've been using Firefox since the 0.7 version when it was named Firebird. I have no technical training or background other than what little I've been able to learn from others when they were using terms that I understood. This 1.5 version of Firefox has some major changes, which the developers tried to test and have most of the wrinkles ironed out before releasing it out of beta. The real acid test is to release it to the average Internet user and then resolve the remaining issues that are reported by way of complaints, either with a work around or a patch. Those of you here who haven't visited the Mozilla Firefox Forum might want to consider doing so and maybe you'll see a topic that fits your particular problem. You can read without registering, or register and ask specific questions. It's no different than posting here at FR. I would help if I could but those who worked on the developement of this version of Firefox are who I would post my questions to if I were having problems. Fortunately for me, 1.5 is running fast with no major problems. Below is the link to the Mozilla Firefox Forum.
http://forums.mozillazine.org/viewforum.php?f=38
I'm not saying don't post questions here, just giving those who don't know another place to look for answers if none are found here at FR.
22
posted on
12/12/2005 6:18:08 PM PST
by
Eagle9
To: Big Giant Head
That web site loads for me in FF 1.5. I have Flash blocked but allowed it to load and it played as it should.The solution to your particular problem is explained at the following linked web page. It depends on what version of Windows you're running.
http://forums.mozillazine.org/viewtopic.php?t=320838
23
posted on
12/12/2005 11:05:23 PM PST
by
Eagle9
To: M0sby
See #16 by chronic_loser. Need more info to help.
24
posted on
12/12/2005 11:08:38 PM PST
by
Eagle9
To: chronic_loser
Thank you CL...
We defrag every Wed and Virus "stuff" (norton corporate is updated weekly too.)
I don't know if this is the "fixit" utility that you mentioned?
I don't know about the RAM part..
I will ask my husband.
He is a HUGE computer GEEK..but isn't running Firefox which is why I thought I would ask you guys instead of him! LOL!
(It is possible that I may have offended his computer geek manly-hood though ;-)
Anyway...the other thing I run into is a HUGE lag-time when I open the program (by double clicking on the desktop icon)
AND...if I leave the program "open" and minimized for a long period (like overnight) sometimes it "sort of" hangs...is very slow and I might have to "force quit" to get out and reopen..
Just wondering if other people are having these "issues"...
THANKS for your FAST reply last time!
Sorry mine WASN'T!
25
posted on
12/13/2005 6:37:32 AM PST
by
M0sby
(((PROUD WIFE of MSgt Edwards USMC)))
To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...
26
posted on
12/13/2005 9:31:34 AM PST
by
ShadowAce
(Linux -- The Ultimate Windows Service Pack)
To: Eagle9
It worked for a few hours.
27
posted on
12/13/2005 11:01:09 AM PST
by
BallyBill
(U.S. Armed Forces.. In It ..To Win It!!)
To: Eagle9
Hey thanks Eagle9! That worked.
28
posted on
12/13/2005 7:32:16 PM PST
by
Big Giant Head
(I should change my tagline to "Big Giant Pancake on my Head")
To: chronic_loser
The problem is the markup's TITLE attribute (in html, the stuff between the <TITLE></TITLE> tags) not the URL.
Navigation: use the links below to view more comments.
first previous 1-20, 21-29 last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson