Firefox 2.0.0.3, and 1.5.0.11 Now Available for Download

page 1, 2  next
You are here:  SillyDog701 > Message Centre > Firefox, SeaMonkey and Netscape > [sdt=13164]
SillyDog701 Forums
Author Message
Ramona
Moderator


Joined: 19 Jun 2002
Posts: 2360
Location: Midwest USA
20 Mar, 2007 3:32 am Firefox 2.0.0.3, and 1.5.0.11 Now Available for Download [sdp=83525]  

Download Version 2.0.0.3 at the FTP site

Download Version 1.5.0.11 at the FTP site


At this early hour, these Versions aren't yet available on the Firefox site, however, I'm certain they will be available shortly, along with the Release Notes.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3


Last edited by Ramona on 10 May, 2007 3:13 pm; edited once(1)
Back to top profile
Mandrake
Moderator


Joined: 13 Sep 2002
Posts: 3637
Location: Australia
20 Mar, 2007 8:28 am [sdp=83534]  

Thanks Ramona. Downloading now. Smile

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.2) Gecko/20070219 Firefox/2.0.0.2

Antec 1200 Case | Core 2 Duo E8200 | Gigabyte X48-DS4 | 1.91TB HDD | 4GB G-Skill/Kingston DDR2-800 | HIS Radeon 4870 Xfire | Zalman 850W PSU | Auzen X-Fi Prelude | Logitech Z-2300 Speakers | Sony 1080P 40" HDTV | MS Natural MultiMedia Keyboard | MS Habu Gaming Mouse
Back to top profile
Fulvio
Moderator


Joined: 19 Jun 2002
Posts: 10532
20 Mar, 2007 11:00 am [sdp=83540]  

I have not taken a deep look, but this does not seem to be the final version, as the Firefox sites declares. Also, why is 2.0.0.3 about 7.2 MB larger than 2.0.0.2?
I was doing a custom installation of 2.0.0.2, while 2.0.0.3 was installed on top of what was left of 1.5.0.10, after installation. Well, the plugins folder of 2.0.0.3 is over 6.5 MB, while 2.0.0.2 is about 3.8. Not enough to account for the difference.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3

"I've got a very poor sense of direction. I keep forgetting which way is forwards."
WinXP, SP2, FF2.0.0.16, FF3.0.1, TB2.0.0.16, IE7.0, Opera9.51, SM1.1.11, Safari3.1.2, Sygate5.6; AVG8.01, JRE1.6_05
Back to top profile
James
diamond member


Joined: 12 Jul 2002
Posts: 1493
20 Mar, 2007 1:20 pm [sdp=83541]  

Why the rush to download? Is 2.0.0.2 somehow at risk already? I'm sincerely confused by this constant rush to grab off the latest updates before they even appear on the Firefox site. Can someone explain this to me?

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.2) Gecko/20070219 Firefox/2.0.0.2

James
It's later than you think.

Firefox 3.0, IE 7
Back to top profile
Don_HH2K
Moderator


Joined: 09 May 2004
Posts: 4535
20 Mar, 2007 1:47 pm [sdp=83542]  

James wrote:
Why the rush to download? Is 2.0.0.2 somehow at risk already? I'm sincerely confused by this constant rush to grab off the latest updates before they even appear on the Firefox site. Can someone explain this to me?


There's no list of fixes on the 2.0.0.3 Release Notes page yet. There are three of six unpatched vulnerabilities on Secunia, though, so I'd like to assume one or more of those have been fixed in the latest release. As far as regular bugfixes go, I couldn't tell you yet.

Also I assume Antony will be by with a speech on how some people need the latest of everything, as well as "Shame on Firefox" and so on.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.8.1.3) Gecko/20070318 BonEcho/2.0.0.3 (ayakawa SSE2-PGU)

Laptop: Turion 64 X2 @ 2GHz, 2GB PC5300, 100GB HD, Radeon X300, 15" LCD, Vista Ultimate x64
Web server: P2 @ 233MHz, 280MB PC66, 20GB HD, 13.3" LCD, Windows Server 2003 x86
Misc. server: MIPS32 @ 216MHz, 16MB PC100, 4MB flash, DD-WRT Linux mipsel
Back to top profile website
Antony
Site Admin


Joined: 18 Jun 2002
Posts: 11915
20 Mar, 2007 1:55 pm [sdp=83543]  

James wrote:
Why the rush to download? Is 2.0.0.2 somehow at risk already? I'm sincerely confused by this constant rush to grab off the latest updates before they even appear on the Firefox site. Can someone explain this to me?
Certainly not me, as most of you know that I don't rush for the latest, and I don't get scared by those vulnerabilities reported.

Firefox 2.0.0.2 is not at risk yet, not even the 2.0.0.0 in my honest opinion. Secunia has been noted of over-exaggerating the situation.

This could be the early release for Firefox Community testers, as mentioned in Firefox Community Beta Program (15th March 2007).

UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.2) Gecko/20070219 Firefox/2.0.0.2

Back to top profile website
Fulvio
Moderator


Joined: 19 Jun 2002
Posts: 10532
20 Mar, 2007 3:57 pm [sdp=83545]  

As far as I know, 2.0.0.3 was to fix some regression encountered with 2.0.0.2. 2.0.0.4 is supposed to fix vulnerabilities. Anyway, I got both version installed.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.2) Gecko/20070219 Firefox/2.0.0.2

"I've got a very poor sense of direction. I keep forgetting which way is forwards."
WinXP, SP2, FF2.0.0.16, FF3.0.1, TB2.0.0.16, IE7.0, Opera9.51, SM1.1.11, Safari3.1.2, Sygate5.6; AVG8.01, JRE1.6_05
Back to top profile
Don_HH2K
Moderator


Joined: 09 May 2004
Posts: 4535
20 Mar, 2007 5:24 pm [sdp=83546]  

Antony wrote:
Firefox 2.0.0.2 is not at risk yet, not even the 2.0.0.0 in my honest opinion. Secunia has been noted of over-exaggerating the situation.


Should I go over the fact that 2.0 Gold has sixteen open holes, seven of which are marked by The Mozilla Foundation themselves as Critical?

Better yet, should I go over the story of Slammer again?

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.8.1.3) Gecko/20070318 BonEcho/2.0.0.3 (ayakawa SSE2-PGU)

Laptop: Turion 64 X2 @ 2GHz, 2GB PC5300, 100GB HD, Radeon X300, 15" LCD, Vista Ultimate x64
Web server: P2 @ 233MHz, 280MB PC66, 20GB HD, 13.3" LCD, Windows Server 2003 x86
Misc. server: MIPS32 @ 216MHz, 16MB PC100, 4MB flash, DD-WRT Linux mipsel
Back to top profile website
Ramona
Moderator


Joined: 19 Jun 2002
Posts: 2360
Location: Midwest USA
20 Mar, 2007 5:52 pm [sdp=83547]  

These are official releases, and available on the Firefox site:

http://www.mozilla.com/en-US/firefox/

http://www.mozilla.com/en-US/firefox/2.0.0.3/releasenotes/

There is never a rush for installing a new release, however, if the new release is a security release, which is the case for 2.0.0.3 and 1.5.0.11, I see no need to continue to use an insecure browser...


Firefox 1.5.0.11: This version of Firefox will be supported until April 24, 2007 with security and stability updates. We strongly encourage all users to upgrade to Firefox 2.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3


Last edited by Ramona on 20 Mar, 2007 5:58 pm; edited once(1)
Back to top profile
Don_HH2K
Moderator


Joined: 09 May 2004
Posts: 4535
20 Mar, 2007 5:56 pm [sdp=83548]  

Thanks Ramona, the list of fixes and so on wasn't available earlier today.

2.0.0.3 fixes a "Low"-rated hole related to FTP handling. While not particularly important (along with three others in the 2.x series, accounting for four "Low" holes), this does bring the vulnerability count in 2.0 Gold up to 17.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.8.1.3) Gecko/20070318 BonEcho/2.0.0.3 (ayakawa SSE2-PGU)

Laptop: Turion 64 X2 @ 2GHz, 2GB PC5300, 100GB HD, Radeon X300, 15" LCD, Vista Ultimate x64
Web server: P2 @ 233MHz, 280MB PC66, 20GB HD, 13.3" LCD, Windows Server 2003 x86
Misc. server: MIPS32 @ 216MHz, 16MB PC100, 4MB flash, DD-WRT Linux mipsel
Back to top profile website
Ramona
Moderator


Joined: 19 Jun 2002
Posts: 2360
Location: Midwest USA
20 Mar, 2007 6:02 pm [sdp=83549]  

This is from the Mozilla Foundation Security Advisories:

Fixed in Firefox 2.0.0.3

MFSA 2007-11 FTP PASV port-scanning

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3

Back to top profile
Antony
Site Admin


Joined: 18 Jun 2002
Posts: 11915
21 Mar, 2007 12:10 am [sdp=83556]  

Less than a month ago, I was being forced to upgrade to Firefox 2.0.0.2, and I have not seen that offensive dialogue as of now.

UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.2) Gecko/20070219 Firefox/2.0.0.2

Back to top profile website
Antony
Site Admin


Joined: 18 Jun 2002
Posts: 11915
21 Mar, 2007 12:46 am [sdp=83557]  

MozInfo701 now has a report on Firefox 2.0.0.3 and 1.5.0.11.

From Mozilla Foundation Security Advisory 2007-11, which is the only minor security fix, it says (with highlight):
Quote:
The FTP protocol includes the PASV (passive) command which is used by Firefox to request an alternate data port. The specification of the FTP protocol allows the server response to include an alternate server address as well, although this is rarely used in practice.

mark@bindshell.net reported that a malicious web page hosted on a specially-coded FTP server could use this feature to perform a rudimentary port-scan of machines inside the firewall of the victim. By itself this causes no harm, but information about an internal network may be useful to an attacker should there be other vulnerabilities present on the network.

Mozilla clients will now ignore the alternate server address.
Just don't use Firefox to browse (or download from) a untrusted FTP server. In fact, there are good FTP software around, just don't use Firefox for FTP task, and you don't need to rush to download.

UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.2) Gecko/20070219 Firefox/2.0.0.2

Back to top profile website
Mandrake
Moderator


Joined: 13 Sep 2002
Posts: 3637
Location: Australia
21 Mar, 2007 2:28 am [sdp=83558]  

Or just download the fix and be happy that you know you're protected from this security flaw. Rolling Eyes

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3

Antec 1200 Case | Core 2 Duo E8200 | Gigabyte X48-DS4 | 1.91TB HDD | 4GB G-Skill/Kingston DDR2-800 | HIS Radeon 4870 Xfire | Zalman 850W PSU | Auzen X-Fi Prelude | Logitech Z-2300 Speakers | Sony 1080P 40" HDTV | MS Natural MultiMedia Keyboard | MS Habu Gaming Mouse
Back to top profile
James
diamond member


Joined: 12 Jul 2002
Posts: 1493
21 Mar, 2007 9:09 am [sdp=83569]  

Well, I've downloaded the update only because it appeared at the official site and because the Update Firefox registered an approved update through the Help section of Firefox. I'm hesitant of applying updates before this time just because they've been rushed out to some ftp server. But it appears we're all safe and secure so.... Smile

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3

James
It's later than you think.

Firefox 3.0, IE 7
Back to top profile
Display posts from previous:   
Reply to topic    Forum Index > Firefox, SeaMonkey and Netscape All times are CST (GMT -6)
page 1 of 2 page 1, 2  next
To add your questions, comments, and for more features and more, please join SillyDog701 Message Centre. It's free! This is SillyDog 701 Message Centre (SD701 Forums).
Harley-Davidson saddle bags - shop online for harley davidson parts & accessories at 20% discount.
Buy Text Links - buy and/or sell text link ads.

Michael Jackson Thriller 25 Your favourite music, radio, music videos, TV shows, movies and more...
Download on iTunes

*Search | FAQ | Rules and Policies | MozInfo701 - Mozilla Information Centre | SD701 Open Directory | Message Board Map | download Netscape