Sponsored Links

Two security flaws discovered in Firefox

A security company has reported two new flaws in the Mozilla Firefox browser that may leave locally saved files vulnerable to outside attacks.

Both flaws were announced by SecuriTeam, a division of Beyond Security, this week. The first flaw lies in Firefox's pop-up blocker feature, according to a SecuriTeam statement on Monday. The browser typically does not allow websites to access files that are stored locally, according to the official report, but this URL permission check is superseded when a Firefox user has turned off pop-up windows manually. As a result, an attacker could use this flaw to steal locally stored files and personal information that might be stored in them.

A possible scenario for such an attack would involve the user clicking on a malicious link that would furtively plant a target file equipped with an exploit code on the computer's hard drive. Then it would display a prompt asking the user to allow a pop-up to appear in order to play a video file or download. The attacker-supplied file would then be loaded thanks to the browser flaw, which could give the attacker local file read privileges.

It appears that this flaw may only apply to older versions of Firefox, prior to the current 2.0 release, but Beyond Security was unavailable for comment on the matter.

The second flaw, announced by SecuriTeam on Wednesday, concerns Firefox's phishing protection feature. With this vulnerability, an adept phisher could fool the browser into believing that a fraudulent site is actually secure by adding particular characters into the URL of its website.

The phishing flaw does appear to apply to the current 2.0.0.1 version of Firefox.

Mozilla was unavailable for comment at the time of writing.

Release notes Firefox Alpha 3 - Known Issues

This list covers some of the known problems with Gran Paradiso Alpha 2. Please read this before reporting any new bugs, and watch for updates as new bugs are discovered.

All Systems

  • The browser may consume excessive amounts of memory after prolonged browsing. In order to better handle memory issues, a new garbage collection system has been implemented. However, as the process of integrating Gecko into this system is still ongoing, there are some known leaks that result in large memory usage when the browser is used for a long period of time. A restart should resolve the problem, which will be fixed in Alpha 3.
  • The Cairo graphics system has drastically changed the way all text and images are rendered from previous versions of Gecko, so occasional misrenderings of non-latin scripts and fonts may occur.
  • The Phishing Protection notification bubble is hidden by the content area (see bug 341950.)

Windows

  • Upscaling images can result in misrendering, causing the edges of the image to appear blurry.

Mac OS X

  • The user's choice of a default font may not always be honored.
  • Font decorations such as underline and strikethrough may be drawn incorrectly.
  • Complex script (ex: Indic) may be misrendered.

Linux and Unix systems

  • Loading any page with Chinese, Japanese or Korean text can hang the browser (see bug 357637).
  • Performance on complex script (ex: Indic) may be slower than previous versions of Gecko.
  • Compatibility issues have been reported when users are not running Xorg 7.0 or better.
  • Users may experience problems when attempting to print complex pages.

Troubleshooting

  • Poorly designed or incompatible Add-ons can cause problems with your browser, including make it crash, slow down page display, etc. If you encounter strange problems relating to parts of the browser no longer working, the browser not starting, windows with strange or distorted appearance, degraded performance, etc, you may be suffering from trouble with your Add-ons. Restart the browser in Safe Mode. On Windows, start using the "Safe Mode" shortcut created in your Start menu or by running firefox.exe -safe-mode. On Linux, start with ./firefox -safe-mode and on Mac OS X, run:

    cd /Applications/GranParadiso.app/Contents/MacOS/
    ./firefox-bin -safe-mode

    When running in Safe Mode, you can disable the add-ons that are causing trouble and then restart to try again.

If you uninstall an extension that is installed with your user profile (i.e. you installed it from a web page) and then wish to install it for all user profiles using the -install-global-extension command line flag, you must restart the browser once to cleanse the profile extensions datasource of traces of that extension before installing with the switch. If you do not do this you may end up with a jammed entry in the Extensions list and will be unable to install the extension globally.

If you encounter strange problems relating to bookmarks, downloads, window placement, toolbars, history, or other settings, it is recommended that you try creating a new profile and attempting to reproduce the problem before filing bugs. Create a new profile by running Firefox with the -P command line argument, choose the "Manage Profiles" button and then choose "Create Profile...". Migrate your settings files (Bookmarks, Saved Passwords, etc) over one by one, checking each time to see if the problems resurface. If you do find a particular profile data file is causing a problem, file a bug and attach the file.

Downloading Gran Paradiso Alpha 2

Downloading Gran Paradiso Alpha 2

Mozilla.org provides Gran Paradiso for Windows, Linux, and Mac OS X in a variety of languages.

For builds for other systems and languages not provided by mozilla.org, see the Contributed Builds section at the end of this document.

Source: Mozilla.org

Release notes Firefox Alpha 3 - Changes in this Development Milestone

Changes in this Development Milestone

Gecko 1.9 Alpha 2 introduces several new features which can be tested by using Gran Paradiso Alpha 2:

  • Core layout code affecting the calculation of widths in tables, floats, and absolutely positioned elements has been rewritten. The code for handling incremental layout of pages (as data arrives over the network, as images load, or as dynamic changes are made) has also been changed extensively. (See the Reflow-Refactoring wiki page for more information.
  • Resolved remaining issues with ACID2 test compliance.
  • Support for the Web Apps 1.0 API for changing stylesheets.
  • The inline-block and inline-table values of CSS 2.1's display property are now implemented.
  • XML documents can now be rendered as they're downloaded instead of only after the full document has been loaded.
  • Greatly improved Mac widgets support since Alpha 1.
  • Improvements in the Cairo graphics layer.

Some of the changes in Gecko 1.9 Alpha 2 will affect the web and platform compatibility of Gran Paradiso Alpha 2:

  • Windows 95, Windows 98, and Windows ME are not supported for Gecko 1.9.
  • OS X 10.2 is no longer supported, and OS X 10.3.9 or better is required.
  • The non-standard JavaScript Script object is no longer supported.
  • Moving DOM nodes between documents now requires a call to importNode or adoptNode as per the DOM specification.

Gran Paradiso release notes

Gran Paradiso Alpha 2 is an early developer milestone for the next major version of Firefox that is being built on top of the next generation of Mozilla's layout engine, Gecko 1.9. Gran Paradiso Alpha 2 is being made available for testing purposes only, and is intended for web application developers and our testing community. Current users of Mozilla Firefox should not use Gran Paradiso Alpha 2.

These Release Notes cover what's new, download and installation instructions, known issues and frequently asked questions for the Gran Paradiso Alpha 2 release. Please read these notes and the bug filing instructions before reporting any bugs to Bugzilla.

Give us your feedback through this feedback form.

Latest post

Sponsored Links

 

Blog published by Blogspot.com
Poster: FireFox Fans

Mozilla®, Firefox® and the Mozilla and Firefox Logos are registered trademarks of the Mozilla Foundation .
For licensing and usage guidelines, please see the Mozilla Trademark Policy .