mopz0506
狐狸大王
狐狸大王
  • UID811
  • 注册日期2004-12-13
  • 最后登录2006-07-13
  • 发帖数539
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度0点
阅读:2904回复:11

FF 的临时补丁,仅建议极度缺乏安全感人士使用

楼主#
更多 发布于:2005-09-11 02:04
就是刚刚那个缓冲区溢出的补丁了。

下载
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.6/patches/307259.xpi

Mozilla offers temporary fix for Firefox flaw

By Joris Evers
http://news.com.com/2102-1002_3-5857511 ... util.print

Story last modified Fri Sep 09 17:32:00 PDT 2005

Responding to the disclosure of a serious Web browser flaw, the Mozilla Foundation offered on Friday a temporary fix to protect Firefox and Mozilla users.

The downloadable fix protects against attacks that take advantage of a new, unpatched flaw that could let attackers secretly run malicious software on users' PCs. The flaw was disclosed late Thursday by security researcher Tom Ferris, sending Mozilla staff into damage-control mode.

The problem has to do with the way the Firefox and Mozilla browsers handle International Domain Names, or IDNs, said Mike Schroepfer, director of engineering at Mozilla. IDNs are domain names that use local language characters. The fix disables support for such Web addresses, he said.

"This is a temporary work-around just to deal with the immediate issue," Schroepfer said. "We're working on a future release in which we will actually fix the problem and re-enable the IDN feature." Switching off IDN support impacts a subset of Firefox and Mozilla users who actually use such special domain names, he said.

Though there is no known attack that takes advantage of the flaw, Mozilla advises Firefox and Mozilla users to disable IDN. "Luckily we do not have any known use of this exploit, but it is fairly critical if there were to be (an attack), so this is a recommended download," Schroepfer said.

Mozilla expects to fix the vulnerability in beta 2 of Firefox 1.5, the next release of the open-source Web browser. Beta 2 is due Oct. 5 and the final release of 1.5 is expected by year's end, Schroepfer said.

In addition to the downloadable fix, Mozilla on its Web site also offers instructions to manually disable IDN: Type "about:config" in the address bar, hit Enter; type "network.enableIDN" in the filter toolbar, hit Enter; right-click the "network.enableIDN" item and select Toggle to change value to false.

IDNs have caused trouble for Mozilla in the past. A Firefox security update in February fixed a flaw that would allow domain spoofing using the special domain names. A spoofed link would seem to be a legitimate address, but instead of taking the victim to the trusted site, the link would lead to a phony Web site.

Though vulnerabilities in Microsoft's Internet Explorer have been the focus of much of the concern, other browsers also have had their fair share of flaws. Security has been a main selling point for Firefox over IE, which has begun to see its market share dip slightly--for the first time in years.

However, Firefox has had its own security woes. Several serious holes in the browser have been plugged since its official release, and experts have said that safe Web browsers don't exist.
mopz0506
狐狸大王
狐狸大王
  • UID811
  • 注册日期2004-12-13
  • 最后登录2006-07-13
  • 发帖数539
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度0点
1楼#
发布于:2005-09-11 02:04
Fedora Core 4 Linux 的 Firefox 版本更新至 1.0.6-1.2,已经打上了这个补丁。
舞间道
千年狐狸
千年狐狸
  • UID41
  • 注册日期2004-11-22
  • 最后登录2022-12-14
  • 发帖数1839
  • 经验-150枚
  • 威望0点
  • 贡献值-352点
  • 好评度-180点
  • 社区居民
2楼#
发布于:2005-09-11 02:04
最新的1.5有没有打上这个补丁???
Skype  支持  Linux  |  MacOS  |  Windows  |  Pocket  PC
abc@home
千年狐狸
千年狐狸
  • UID6047
  • 注册日期2005-05-16
  • 最后登录2011-01-01
  • 发帖数1681
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度1点
3楼#
发布于:2005-09-11 02:04
在 about:config 取消 idn 支持就可以。那个 xpi 也只是改这个设置,没需要。

http://forums.mozillazine.org/viewtopic.php?t=315499



WINXP SP2 MAXTHON (UNICODE) PROXOMITRON
舞间道
千年狐狸
千年狐狸
  • UID41
  • 注册日期2004-11-22
  • 最后登录2022-12-14
  • 发帖数1839
  • 经验-150枚
  • 威望0点
  • 贡献值-352点
  • 好评度-180点
  • 社区居民
4楼#
发布于:2005-09-11 02:04
原来如此啊.........
Skype  支持  Linux  |  MacOS  |  Windows  |  Pocket  PC
darkpro
火狐狸
火狐狸
  • UID6575
  • 注册日期2005-06-06
  • 最后登录2017-11-15
  • 发帖数158
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度0点
  • 社区居民
5楼#
发布于:2005-09-11 02:04
abc@home:在 about:config 取消 idn 支持就可以。那个 xpi 也只是改这个设置,没需要。

http://forums.mozillazine.org/viewtopic.php?t=315499
回到原帖


ABC老兄,有件事情我一直搞不明白,怎么你的FIREFOX是WACKO核心,大家用的FIREFOX都是GECKO核心呢?我在GOOGLE上也没找到这个WACKO是什么东东?可以满足一下我的好奇心吗?谢谢!
听涛看海
千年狐狸
千年狐狸
  • UID190
  • 注册日期2004-11-26
  • 最后登录2012-10-12
  • 发帖数1567
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度0点
6楼#
发布于:2005-09-11 02:04
Fx的一大特点就是可改造性比较强,只要你懂就可以按照自己的想法来做。
客游
千年狐狸
千年狐狸
  • UID5736
  • 注册日期2005-05-06
  • 最后登录2012-10-09
  • 发帖数1363
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度0点
7楼#
发布于:2005-09-11 02:04
同意!
三翻领
禁止发言
禁止发言
  • UID6501
  • 注册日期2005-06-02
  • 最后登录2017-11-30
  • 发帖数2796
  • 经验-5234枚
  • 威望0点
  • 贡献值-10494点
  • 好评度-5257点
8楼#
发布于:2005-09-11 02:04
用户被禁言,该主题自动屏蔽!
abc@home
千年狐狸
千年狐狸
  • UID6047
  • 注册日期2005-05-16
  • 最后登录2011-01-01
  • 发帖数1681
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度1点
9楼#
发布于:2005-09-11 02:04
darkpro

ABC老兄,有件事情我一直搞不明白,怎么你的FIREFOX是WACKO核心,大家用的FIREFOX都是GECKO核心呢?我在GOOGLE上也没找到这个WACKO是什么东东?可以满足一下我的好奇心吗?谢谢!
回到原帖

嘻,是 gecko 内核的。wacko 是用 proxomitron 改的。



WINXP SP2 MAXTHON (UNICODE) PROXOMITRON
darkpro
火狐狸
火狐狸
  • UID6575
  • 注册日期2005-06-06
  • 最后登录2017-11-15
  • 发帖数158
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度0点
  • 社区居民
10楼#
发布于:2005-09-11 02:04
darkpro
嘻,是 gecko 内核的。wacko 是用 proxomitron 改的。
回到原帖


牛!proxomitron是web filter吧?支持Deer Park吗?proxomitron有哪些功能呢?
darkpro
火狐狸
火狐狸
  • UID6575
  • 注册日期2005-06-06
  • 最后登录2017-11-15
  • 发帖数158
  • 经验10枚
  • 威望0点
  • 贡献值0点
  • 好评度0点
  • 社区居民
11楼#
发布于:2005-09-11 02:04
还有那个WACKO是怎么改出来的啊?我也想想玩玩。请多指教。
游客

返回顶部