Hands-On Report--Firefox 2.0.0.4, a Security Update
Firefox 2.0.0.4 is a security update that fixes these security issues:
MFSA 2007-17 XUL Popup Spoofing
MFSA 2007-16 XSS using addEventListener
MFSA 2007-14 Path Abuse in Cookies
MFSA 2007-13 Persistent Autocomplete Denial of Service
MFSA 2007-12 Crashes with evidence of memory corruption (rv:1.8.0.12/1.8.1.4)
According to Mozilla, these issues remain in the Mac OS X version of Firefox:
- The "Close Other Tabs" action on the shortcut menu of a tab can fail with an error when more than 20 tabs are open.
- Some users have reported problems viewing Macromedia Flash content on Intel Mac computers. To work around this problem, users can remove or move the PowerPC version of "Flash Player Enabler.plugin from /Library/Internet Plug-Ins.
- After installing a new plug-in, Firefox may continue to display information for the older version of the plug-in in about:plugins. If this happens, quit Firefox, delete the "pluginreg.dat" file from your profile folder, and relaunch Firefox.
- Java does not run on Intel Core processors under Rosetta.
- There is no Talkback on Intel-based Macs when running natively or under Rosetta. The Apple Crash report program should launch in the event of application crashes.
We occasionally use Firefox in lieu of Safari so we downloaded v2.0.0.4 from within the application and installed it on an Intel-based Mac mini and a MacBook Pro Core 2 Duo without any problems. Then, we used Firefox 2.0.0.4 for several hours without noting an issue.
Mozilla also released Firefox 1.5.0.12, which is expected to be the final release of the Firefox 1.5 line. The fixed security flaws are detailed in the Firefox 1.5.0.12 section of the Mozilla Foundation Security Advisories page.
With SeaMonkey and Firefox already updated, Mozilla's email client Thunderbird should be updated soon. [Bill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?