<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Firefox 3.0.2 Released in Security</title>
<link>http://www.dslreports.com/forum/r21160263</link>
<description></description>
<language>en</language>
<pubDate>Mon, 14 Dec 2009 18:35:40 EDT</pubDate>
<lastBuildDate>Mon, 14 Dec 2009 18:35:40 EDT</lastBuildDate>

<item>
<title>Re: Firefox 3.0.2 Released</title>
<link>http://www.dslreports.com/forum/remark,21173591</link>
<description><![CDATA[<A HREF="/useremail/u/914341"><b>chachazz</b></A> : The candidate builds are already 'ready for testing':<br>Firefox 3.0.3: &raquo;<small>ftp</small>://<A HREF="ftp://ftp.mozilla.org/pub/firefox/nightly/3.0.3-candidates/build1/">ftp.mozilla.org/pub/firefox/nigh&middot;&middot;&middot;/build1/</A><br>  <blockquote><small>quote:</small><hr>Please hammer on this build mercilessly to make sure that your stuff works with it!  If you notice things that worked in Firefox 3 or Firefox 2.0.0.17 and do not work in this release, we would like to know about it right away.<br><br><b>Read the Release Notes:</b><br>Firefox 3.0.3: &raquo;<A HREF="http://en-us.www.mozilla.com/en-US/firefox/3.0.3/releasenotes/" >en-us.www.mozilla.com/en-US/fire&middot;&middot;&middot;senotes/</A> <br><br>Bugs specifically addressed in this build:<br># bug 451155 - Password manager does not work correctly on IDN site whose name contains any character over U+0100<br># bug 454708 - storage-Legacy can throw when calling ConvertToUnicode <br><br>(email)<br>marcia, on behalf of<br>Team Mozilla QA <br><hr></blockquote><br><br><small>--<br>Gladiator Security Forum: <A HREF="http://www.gladiator-antivirus.com/">www.gladiator-antivirus.com/</a><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21173591</guid>
<pubDate>Fri, 26 Sep 2008 14:57:38 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 Released</title>
<link>http://www.dslreports.com/forum/remark,21165815</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> : Indeed it's good to patch up all of these holes, but also this means that when reading stats on number of discovered vulnerabilities, one needs to keep in mind the severity of those discovered too.... Being able to fool someone into dragging their mouse is not quite the same as a drive-by download and execution vulnerability.<br><small>--<br>Ubuntu MOTU Developer and Forums Council</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21165815</guid>
<pubDate>Thu, 25 Sep 2008 09:15:02 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 Released</title>
<link>http://www.dslreports.com/forum/remark,21165801</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : <div class="bquote"><small>said by  jdong <A HREF="/useremail/u/655964"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>  <blockquote><small>quote:</small><hr>Mozilla developer Paul Nickerson reported a variant of a click-hijacking vulnerability discovered in Internet Explorer by Liu Die Yu. The vulnerability allowed an attacker to move the content window while the mouse was being clicked, causing an item to be dragged rather than clicked-on. This issue could potentially be used to force a user to download a file or perform other drag-and-drop actions.<br><hr></blockquote><br><br>Am I the only one that finds some of the vulnerability scenarios these days to be a stretch to the point that they're funny?<br> </div>a stretch maybe, but alot of stupid users, and alot of smart bad guys these days]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21165801</guid>
<pubDate>Thu, 25 Sep 2008 09:11:51 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 Released</title>
<link>http://www.dslreports.com/forum/remark,21165719</link>
<description><![CDATA[<A HREF="/useremail/u/655964"><b>jdong</b></A> :  <blockquote><small>quote:</small><hr>Mozilla developer Paul Nickerson reported a variant of a click-hijacking vulnerability discovered in Internet Explorer by Liu Die Yu. The vulnerability allowed an attacker to move the content window while the mouse was being clicked, causing an item to be dragged rather than clicked-on. This issue could potentially be used to force a user to download a file or perform other drag-and-drop actions.<br><hr></blockquote><br><br>Am I the only one that finds some of the vulnerability scenarios these days to be a stretch to the point that they're funny?<br><small>--<br>Ubuntu MOTU Developer and Forums Council</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21165719</guid>
<pubDate>Thu, 25 Sep 2008 08:52:22 EDT</pubDate>
</item>

<item>
<title>Firefox 3.0.3 required and underway</title>
<link>http://www.dslreports.com/forum/remark,21165694</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : From <A HREF="http://groups.google.com/group/mozilla.dev.planning/browse_thread/thread/e047739c7e3345f0#">mozilla.dev.planning</a><br><br>From: Mike Beltzner <br>Date: Wed, 24 Sep 2008 21:38:37 -0400<br>Local: Wed, Sep 24 2008 9:38 pm<br>Subject: Firefox 3.0.3 required and underway<br><br>Hey everyone,<br><br>Shortly after releasing Firefox 3.0.2 our QA and Support teams began seeing reports of problems certain users were having with the Firefox Password Manager. This was being caused by non-ASCII data (in domains, logins or passwords) saved as something other than UTF-8 failing to convert back to Unicode (see bug 454708) which was a regression from a fix to make the Password Manager work on IDN sites with characters over U+0100 (see bug 451155).<br><br>The symptom is that users who have password data stores with non-ASCII data saved as something other than UTF-8 (more common for people who have saved passwords on IDN  domains or non en-US domains) will not be able to access their saved passwords or create any new saved passwords. There is no permanent dataloss, the saved data is just inaccessible. While this doesn't affect all Firefox users, it is a significant regression and has triggered a fast-release Firefox 3.0.3 which will contain a single fix for this issue. Once released, this will restore the functionality for all users.<br><br>The fix has been landed and tested, and builds are coming out and being delivered to QA today. We hope to be releasing updates on the beta channel by early next week and issuing a release soon thereafter.<br><br>cheers,<br>mike]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21165694</guid>
<pubDate>Thu, 25 Sep 2008 08:46:29 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 &#x26; 2.0.0.17 Released</title>
<link>http://www.dslreports.com/forum/remark,21162304</link>
<description><![CDATA[<A HREF="/useremail/u/170670"><b>JTM1051</b></A> : <div class="bquote"><small>said by  TKJunkMail <A HREF="/useremail/u/594412"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>More English like description of the security vulnerabilities that were patched.<br><br>&raquo;<A HREF="http://news.cnet.com/8301-1009_3-10049925-83.html?part=rss&subj=news&tag=2547-1_3-0-20" >news.cnet.com/8301-1009_3-100499&middot;&middot;&middot;1_3-0-20</A><br> </div>Just a FYI, at the <A HREF="http://www.mozilla.org/security/known-vulnerabilities/firefox20.html#firefox2.0.0.17"><u>Vulnerabilities Fixed</u></a>, the links (e.g., "<A HREF="http://www.mozilla.org/security/announce/2008/mfsa2008-45.html"><u>MFSA 2008-45</u></a>) have more detailed descriptions -- IMHO looks like CNET basically used the same descriptions. ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21162304</guid>
<pubDate>Wed, 24 Sep 2008 16:25:06 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 &#x26; 2.0.0.17 Released</title>
<link>http://www.dslreports.com/forum/remark,21162011</link>
<description><![CDATA[<A HREF="/useremail/u/594412"><b>TKJunkMail</b></A> : More English like description of the security vulnerabilities that were patched.<br><br>&raquo;<A HREF="http://news.cnet.com/8301-1009_3-10049925-83.html?part=rss&subj=news&tag=2547-1_3-0-20" >news.cnet.com/8301-1009_3-100499&middot;&middot;&middot;1_3-0-20</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21162011</guid>
<pubDate>Wed, 24 Sep 2008 15:36:32 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 Released</title>
<link>http://www.dslreports.com/forum/remark,21161002</link>
<description><![CDATA[<A HREF="/useremail/u/1294421"><b>roc5955</b></A> : Strange, as I was reading this message, I decided to see what version I have, and ver. 3.02 is downloading itself, as I type this!<br><small>--<br>"Understanding is a three-edged sword."</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21161002</guid>
<pubDate>Wed, 24 Sep 2008 12:46:24 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 Released</title>
<link>http://www.dslreports.com/forum/remark,21160568</link>
<description><![CDATA[<A HREF="/useremail/u/766601"><b>avd706</b></A> : 3.0.2 build 6]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21160568</guid>
<pubDate>Wed, 24 Sep 2008 11:45:19 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 &#x26; 2.0.0.17 Released</title>
<link>http://www.dslreports.com/forum/remark,21160370</link>
<description><![CDATA[<A HREF="/useremail/u/170670"><b>JTM1051</b></A> : Also Fx 2.0.0.17 released:<br><br><A HREF="http://www.mozilla.org/security/known-vulnerabilities/firefox20.html#firefox2.0.0.17"><u>Vulnerabilities Fixed</u></a><br>MFSA 2008-45  XBM image uninitialized memory reading<br>MFSA 2008-44  resource: traversal vulnerabilities<br>MFSA 2008-43  BOM characters stripped from JavaScript before execution<br>MFSA 2008-42  Crashes with evidence of memory corruption (rv:1.9.0.2/1.8.1.17)<br>MFSA 2008-41  Privilege escalation via XPCnativeWrapper pollution<br>MFSA 2008-40  Forced mouse drag<br>MFSA 2008-39  Privilege escalation using feed preview page and XSS flaw<br>MFSA 2008-38  nsXMLDocument::OnChannelRedirect() same-origin violation<br>MFSA 2008-37  UTF-8 URL stack buffer overflow<br><br><A HREF="http://www.mozilla.com/en-US/firefox/all-older.html"><u>Fx 2.x Download Page</u></a>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21160370</guid>
<pubDate>Wed, 24 Sep 2008 11:15:50 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.2 Released</title>
<link>http://www.dslreports.com/forum/remark,21160346</link>
<description><![CDATA[<A HREF="/useremail/u/1404903"><b>DrModem</b></A> : Hopefully this will fix those annoying crashes that wipe my cache all the time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21160346</guid>
<pubDate>Wed, 24 Sep 2008 11:11:54 EDT</pubDate>
</item>

<item>
<title>Firefox 3.0.2 Released</title>
<link>http://www.dslreports.com/forum/remark,21160263</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : <A HREF="http://www.mozilla.org/security/known-vulnerabilities/firefox30.html#firefox3.0.2">Fixed in Firefox 3.0.2</a><br>MFSA 2008-44 resource: traversal vulnerabilities<br>MFSA 2008-43 BOM characters stripped from JavaScript before execution<br>MFSA 2008-42 Crashes with evidence of memory corruption (rv:1.9.0.2/1.8.1.17)<br>MFSA 2008-41 Privilege escalation via XPCnativeWrapper pollution<br>MFSA 2008-40 Forced mouse drag]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21160263</guid>
<pubDate>Wed, 24 Sep 2008 10:58:29 EDT</pubDate>
</item>

</channel>
</rss>
