Find the answer to your Linux question:
Results 1 to 8 of 8
http://tomshardware.co.uk/2006/10/02...ecurity_issue/ Seems pretty serious. Not sure how worried we should be...
  1. #1
    Linux User zba78's Avatar
    Join Date
    Feb 2004
    Location
    Birmingham, England
    Posts
    335

    Critical Firefox flaw exposed

    http://tomshardware.co.uk/2006/10/02...ecurity_issue/

    Seems pretty serious. Not sure how worried we should be
    Ubuntu Jaunty :: Arch Linux (current) :: Acer Aspire 1692WMLi

  2. #2
    Linux Guru techieMoe's Avatar
    Join Date
    Aug 2004
    Location
    Texas
    Posts
    9,496
    I use NoScript to block Javascript from everywhere but sites I absolutely trust. Move along. Nothing to see here.
    Registered Linux user #270181
    TechieMoe's Tech Rants

  3. #3
    Trusted Penguin Roxoff's Avatar
    Join Date
    Aug 2005
    Location
    Nottingham, England
    Posts
    3,391
    What, you mean they could get access to my computer and start running things as me, as a regular user?

    Funny, but this doesn't fill me with the cold dread it would do if I were a Windows user.
    Linux user #126863 - see http://linuxcounter.net/

  4. #4
    Linux Guru techieMoe's Avatar
    Join Date
    Aug 2004
    Location
    Texas
    Posts
    9,496
    Quote Originally Posted by Roxoff
    What, you mean they could get access to my computer and start running things as me, as a regular user?

    Funny, but this doesn't fill me with the cold dread it would do if I were a Windows user.
    Actually, the details of the exploit on MozDev says the only thing it can do right now is use up your memory and crash your browser. One of the fellows who showed this exploit has said:

    I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven’t used it to take over anyone else’s computer and execute arbitrary code.
    But yes, as Roxoff said, even if this were the case most Linux users aren't exactly quaking in their boots.
    Registered Linux user #270181
    TechieMoe's Tech Rants

  5. #5
    Linux Guru fingal's Avatar
    Join Date
    Jul 2003
    Location
    Birmingham - UK
    Posts
    1,539
    No worries here: I haven't had a FF crash in ages and I've submitted several bug reports (no real effort involved as FF gives you the option to do this very readily).

    I also use the NoScript plugin. All in all we're pretty secure.
    I am always doing that which I can not do, in order that I may learn how to do it. - Pablo Picasso

  6. #6
    Linux Newbie easuter's Avatar
    Join Date
    Jan 2006
    Location
    Portugal
    Posts
    194
    the article has a "Ha!! you thought you were using a better browser...fools!" tone to it......

    i don't think all the vulnerabilities found in IE would fit in a 1000 page book, and they aren't publicly played up. actually, i hardly ever hear about specific IE vulns on sites like that.

    Firefox Web browser, commonly perceived as the safer and more customizable alternative to market leader Internet Explorer, is critically flawed.
    it even has a security map so all the dumb-witted can "see" the HUGE hole firefox has.

    the guy who wrote the artile is obviously a windows zealot.
    All Empires rise and fall. The Microsoft Empire has already risen, only one way to go now...

  7. #7
    Linux Guru techieMoe's Avatar
    Join Date
    Aug 2004
    Location
    Texas
    Posts
    9,496
    Quote Originally Posted by easuter
    the guy who wrote the artile is obviously a windows zealot.
    I think it has more to do with "security firm employee ego" than anything. This is the second time it seems that people working for security firms have made a public spectacle of a flaw they discovered, only to make asses out of themselves in a misguided attempt to gain notoreity and (perhaps) a better job. The Maynor/Ellch/Ou MacBook Hack fiasco is a perfect example of this. The difference between them and these two is that the Firefox flaw seems to actually be real. I take fantastic statements about security flaws by a company that makes money off of them with a very large grain of salt, personally.
    Registered Linux user #270181
    TechieMoe's Tech Rants

  8. #8
    Linux Guru
    Join Date
    Nov 2004
    Posts
    6,110
    Don't worry about it folks - check this out - Slashdot Article

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •