dslreports logo
Search similar:


uniqs
17777

Name Game
Premium Member
join:2002-07-07
Grand Rapids, MI
kudos:7

1 edit

Name Game

Premium Member

Firefox 5 fixes security and improves browsing

Posted on 21 June 2011.Mozilla released Firefox 5.0 that fixes several security issues, stability issues and introduces new features.

Privacy-aware users will be happy to learn that the Do-Not-Track header preference has been moved to increase discoverability.

The latest version of Firefox has the following changes:
Added support for CSS animations
Tuned HTTP idle connection logic for increased performance
Improved canvas, JavaScript, memory, and networking performance
Improved standards support for HTML5, XHR, MathML, SMIL, and canvas
Improved spell checking for some locales
Improved desktop environment integration for Linux users
WebGL content can no longer load cross-domain textures
Background tabs have setTimeout and setInterval clamped to 1000ms to improve performance.

»www.net-security.org/sec ··· id=11201

Download your flavor here..
»www.mozilla.com/en-US/fi ··· all.html

--
Gladiator Security Forum
»www.gladiator-antivirus.com/
redwolfe_98
Premium Member
join:2001-06-11
kudos:3

redwolfe_98

Premium Member

thanks name game i appreciate your posts..

»www.mozilla.org/security ··· fox.html

Fixed in Firefox 5
MFSA 2011-28 Non-whitelisted site can trigger xpinstall
MFSA 2011-27 XSS encoding hazard with inline SVG
MFSA 2011-26 Multiple WebGL crashes
MFSA 2011-25 Stealing of cross-domain images using WebGL textures
MFSA 2011-22 Integer overflow and arbitrary code execution in Array.reduceRight()
MFSA 2011-21 Memory corruption due to multipart/x-mixed-replace images
MFSA 2011-20 Use-after-free vulnerability when viewing XUL document with script disabled
MFSA 2011-19 Miscellaneous memory safety hazards (rv:3.0/1.9.2.18)
Fixed in Firefox 4.0.1
MFSA 2011-18 XSLT generate-id() function heap address leak
MFSA 2011-17 WebGLES vulnerabilities
MFSA 2011-12 Miscellaneous memory safety hazards (rv:2.0.1/ 1.9.2.17/ 1.9.1.19)

antdude
A Ninja Ant
VIP
join:2001-03-25
United State
kudos:5

antdude to Name Game

VIP

to Name Game
Does this version break extensions, addons, and plugins?
redwolfe_98
Premium Member
join:2001-06-11
kudos:3

redwolfe_98 to Name Game

Premium Member

to Name Game
as might be expected, there is also an update for FF build 3.6.x:

»www.mozilla.org/security ··· x36.html

Fixed in Firefox 3.6.18
MFSA 2011-24 Cookie isolation error
MFSA 2011-23 Multiple dangling pointer vulnerabilities
MFSA 2011-22 Integer overflow and arbitrary code execution in Array.reduceRight()
MFSA 2011-21 Memory corruption due to multipart/x-mixed-replace images
MFSA 2011-20 Use-after-free vulnerability when viewing XUL document with script disabled
MFSA 2011-19 Miscellaneous memory safety hazards (rv:3.0/1.9.2.18)
Marsman
join:2004-11-10

Marsman to antdude

Member

to antdude
Temporary broke only ColorfulTabs here but after a repack & bump it works like a charm again!

Cudni
La Merma - Vigilado
MVM
join:2003-12-20
Someshire
kudos:13

Cudni to antdude

MVM

to antdude
said by antdude:

Does this version break extensions, addons, and plugins?

only some

Cudni
KoRnGtL15
Premium Member
join:2007-01-04
Grants Pass, OR
kudos:1

KoRnGtL15 to Marsman

Premium Member

to Marsman
Did not break ColorfulTabs for me....

jadinolf
I love you Fred
Premium Member
join:2005-07-09
Ojai, CA
kudos:8

jadinolf to Name Game

Premium Member

to Name Game
Updated all 5 computers today.

I'm too much of a noob to see the difference but any improvements are welcome.

Thanks
--
Printed on 100% recycled bytes
Marsman
join:2004-11-10

Marsman to KoRnGtL15

Member

to KoRnGtL15
I'm running a repacked & bumped CT V4.8.1.6.2 & out of curiosity may I ask what version do you have installed.
KoRnGtL15
Premium Member
join:2007-01-04
Grants Pass, OR
kudos:1

KoRnGtL15

Premium Member

4.8.1.6.2.2
Marsman
join:2004-11-10

Marsman

Member

Thx & much appreciated!
KoRnGtL15
Premium Member
join:2007-01-04
Grants Pass, OR
kudos:1

KoRnGtL15

Premium Member

No problem.

antdude
A Ninja Ant
VIP
join:2001-03-25
United State
kudos:5
·Time Warner Cable

antdude to Name Game

VIP

to Name Game

For those who use Norton 2011 and Norton 360 v5 products ...

A LiveUpdate to support Firefox v5. See for more details on Norton product:

»community.norton.com/t5/ ··· p/478160

»community.norton.com/t5/ ··· p/478162
--
Ant @ »antfarm.ma.cx and »aqfl.net. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer
samurai123
join:2007-07-15
Santa Clara, CA

samurai123 to Name Game

Member

to Name Game

Re: Firefox 5 fixes security and improves browsing

When there will be a 64-bit version of FF for Windows 64bit?

Thanks

rcdailey
Dragoonfly
Premium Member
join:2005-03-29
Rialto, CA

rcdailey to Name Game

Premium Member

to Name Game
When I saw the title in the message list, I checked for updates and got it.
--
Don't let the pluperfect be the enemy of the perfect.
rcdailey

rcdailey to antdude

Premium Member

to antdude
None of mine were broken, and I have had them broken with previous updates. I think the authors were ready for 5.0.
--
Don't let the pluperfect be the enemy of the perfect.

Dude111
An Awesome Dude
Premium Member
join:2003-08-04
kudos:14

Dude111 to Name Game

Premium Member

to Name Game

 

I dont see how adding a DO NOT TRACK to the header will make sites comply,thats stupid to think that would do any good @ all (IT MIGHT MAKE YOU MORE NOTICABLE)

In any event does anyone know what this header is?? ILL TRY ADDING IT TO MY BROWSER AND SEE WHAT HAPPENS....

Ultimatly deleting cookies is the thing to always do!
lawrence171
Evilly Yours - Evilness
join:2001-12-24
Canada

lawrence171 to Name Game

Member

to Name Game

Re: Firefox 5 fixes security and improves browsing

How can I disable WebGL? I have considerable amount of reserves about this technology.
--
What I used to be I no longer am... God, why can't you freeze time for my sake?

Noah Vail
Oh God please no.
Premium Member
join:2004-12-10
SouthAmerica
kudos:3

Noah Vail to Name Game

Premium Member

to Name Game
I'm going to upgrade my 3.6.17.

I'm going to seriously miss my Netcraft bar if it isn't there.
And my UserAgent Switcher
And my Forcast bar enhanced
And especially my Remember Certification Exception.

Time to start editing some xpi files; I'll bet.

I'm holding you personally responsible Name Game , if I'm less than completely satisfied.

NV
--
Any Goal that is Driven by Animosity, is Empowered through Deceit.
Noah Vail

Noah Vail to Name Game

Premium Member

to Name Game
I have returned - and with less than a full measure of satisfaction.

OK. It turned out better than I feared. Netcraft stuck around.
So did UserAgent Switcher - that's good.

Bit I lost TinEye, HTTPFox and my beloved Remember Certificate Exception.
Maybe Certs will be handled intelligently and I won't need RCE.
(I doubt it. IE9 still SUCKS at handling self signed certs)

HTTPFox will be sorely missed. So will TinEye. I'll hack their xpi's and see if they might still function.

My first action was to download Status-4-evar. I MUST have a status bar.

Other than all that...
It looks just like FF4. And it came out - what? like 45 minutes - after FF4 was released?

If this is the magical release that keeps my RAM Usage from ballooning up to a petabyte; then I'll be happy.
for 10 minutes.
if I get Ice Cream along with it.

NV
--
Any Goal that is Driven by Animosity, is Empowered through Deceit.

MarkAW
Barry White
Premium Member
join:2001-08-27
Canada
kudos:16

MarkAW to antdude

Premium Member

to antdude
said by antdude:

Does this version break extensions, addons, and plugins?

Yes it did for me and others.
»Re: [FireFox] Firefox 5.0 Final

Noah Vail
Oh God please no.
Premium Member
join:2004-12-10
SouthAmerica
kudos:3

Noah Vail

Premium Member

said by MarkAW:

said by antdude:

Does this version break extensions, addons, and plugins?

Yes it did for me and others.

My Disabled list.




Too tired to hack the xpi-s tonight. I'll try tomorrow.

NV
--
Any Goal that is Driven by Animosity, is Empowered through Deceit.

Mannus
Premium Member
join:2005-10-25
Fort Wayne, IN

Mannus to Name Game

Premium Member

to Name Game
I am gonna wait to update to 5.0. Google toolbar and AVG Safe search are not compatible yet.

chachazz
Premium Member
join:2003-12-14
kudos:10
·TELUS

chachazz to Noah Vail

Premium Member

to Noah Vail
Install Compatability Reporter - everyone
»addons.mozilla.org/en-US ··· ?src=api
--
Gladiator Security Forum: www.gladiator-antivirus.com/
GuruGuy
join:2002-12-16
Atlanta, GA

GuruGuy to lawrence171

Member

to lawrence171
said by lawrence171:

How can I disable WebGL? I have considerable amount of reserves about this technology.

»New graphics engines imperil users of Firefox and Chrome

In Firefox 4, type about:config (minus the quotes) into the address bar and set webgl.disabled to true. In Chrome, get to the command line of your operating system and add the --disable-webgl flag to the Chrome command. On a Windows machine, the command line would be "chrome.exe --disable-webgl". ®
--
GuruGuy
Mele20
Premium Member
join:2001-06-05
Hilo, HI
kudos:8

Mele20 to Name Game

Premium Member

to Name Game
Ugh. And Mel has still not fixed MR Tech to be fully compatible with Fx4 much less Fx5 where evidently the extension is badly needed.

Oh well, I used Fx 1.5 for MANY YEARS. I have no interest in playing Mozilla's latest kindergarten game. I like Fx 4. I will use it until I no longer like it. Screw Mozilla and their new, extremely silly updating schedule.

Why Mozilla would be threatened by Google and decide to imitate Chrome's silly and extremely empty rapid updates is beyond me. Iron/Chrome has made NO signifiicant changes since I first got Iron at 5.x and now it is at 12.x and wasn 't worth the bother as almost nothing has changed that is important. And Mozilla wants to imitate Google's schedule? Mozilla should ignore other browsers and stick to what is good for Fx which is not updating every time you turn around. Updates should be once a year at the most for any DECENT browser.

--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson

red2
@fastwebnet.it

red2

Anon

As I don't keep up with this the way some of you do, can someone simply lay out what are the security advantages or major benefits of moving from the 3.6.17 platform to FF 4 or 5? Is there a chart somewhere which lays out what benefits you get/lose?

If they keeping releasing updates for the 3.6 platform does this mean that versions 4 and 5 simply introduce some new features and a new interface that some may or may not like, but that the latest version of each has comparative security?

Xioden
Premium Member
join:2008-06-10
Monticello, NY
kudos:1

Xioden

Premium Member

Right now, the security updates are still being rolled out to 3.6. So you don't really need to update to 4 or 5 for that reason (for now at least).

If all of your extensions are FF4/5 compatable, there really isn't any harm in upgrading. As far as the new appearence, FF 4 at least can be made to look like 3.6 quite easily with just a theme and a status bar addon covering most of it (this site covers it pretty well).

Noah Vail
Oh God please no.
Premium Member
join:2004-12-10
SouthAmerica
kudos:3

Noah Vail to red2

Premium Member

to red2
said by red2 :

As I don't keep up with this the way some of you do, can someone simply lay out what are the security advantages or major benefits of moving from the 3.6.17 platform to FF 4 or 5?

My hope was to get a handle on FF's historically out of control memory usage.

However, here I sit with 3 tabs open and FF using 246,244K of memory.

Nv
--
Any Goal that is Driven by Animosity, is Empowered through Deceit.

red2
@fastwebnet.it

red2

Anon

said by Noah Vail:

However, here I sit with 3 tabs open and FF using 246,244K of memory.
Nv

I hear you. I haven't noticed ANY improvement in the memory issue over the past few builds in the 3.6 platform.

What is surprising to me is when applications seem to be rolled out for "defensive" reasons, similar to when product lines get extended just to have a product cover every possible pricepoint to combat competition. When there are 3 versions of the same browser, I wonder if it is simply done to capture more market share rather than introduce real improvements, and so if someone saw some real improvements I wondered what they are.