{"id":198,"date":"2004-10-06T03:35:00","date_gmt":"2004-10-06T03:35:00","guid":{"rendered":"http:\/\/jclark.org\/weblog\/WebDev\/Browsers\/critical2.html"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-30T04:00:00","slug":"critical2","status":"publish","type":"post","link":"https:\/\/jclark.org\/weblog\/2004\/10\/06\/critical2\/","title":{"rendered":"Critical Update Followup"},"content":{"rendered":"<p>On Saturday, I <a href=\"http:\/\/jclark.org\/weblog\/WebDev\/Browsers\/critical.html\">reported on the first Critical Update<\/a> for Firefox.  In addition to being pleased with the rapid response and integrated update notification, I was concerned about the fact that almost no detail was given on the vulnerability, either in the update tool or on any of several Mozilla websites.  At the time, I said the following:<\/p>\n<blockquote>\n<p>So there&#8217;s some kind of file download exploit possible, but the details are omitted. I&#8217;m no security expert, but I though best practice was to release as much information as possible. I don&#8217;t mind that Firefox has a vulnerability; no software is perfect. I&#8217;m impressed by the level of response and the integrated update system. At the same time, I&#8217;d rather see more information about the problem and solution (or even a link to same) than statistics spin.<\/p>\n<\/blockquote>\n<p>On Sunday or Monday, I came accross the Bugzilla Bug# for the vulnerability (probably via <a href=\"http:\/\/www.squarefree.com\/burningedge\/\">Burning Edge<\/a>).  When I tried to click through to view the bug report, I got a big red screen with a message indicating the bug was permissioned, and I didn&#8217;t have perms to view it.  This was something I&#8217;d not seen before at Bugzilla, and I&#8217;d intended to blog about it here.<\/p>\n<p>Today there&#8217;s more information.  Early this morning, Burning Edge <a href=\"http:\/\/www.squarefree.com\/burningedge\/archives\/000589.html\">reported &#8220;Bug 259708 fully disclosed&#8221;<\/a>.  I&#8217;ve now read <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=259708\">bug 259708<\/a> and the comment thread, and I have to say <strong>I was wrong.<\/strong>  The bug in question was pretty nasty, and would allow a download link on a web page (assuming you choose to save the file) to delete every file in the target directory.  Ouch!  The Mozilla folks decided to restrict access to the specifics while a patch was cranked out.  They also decided to wait a couple days for the patch to be downloaded before disclosing the bug, allowing users to put a fix in place.  The team acted quickly in the best interest of the users, and released all of the information in a timely manner without further jeopardizing users&#8217; data.  <\/p>\n<p>Nice Job, Guys.<\/p>","protected":false},"excerpt":{"rendered":"<p>On Saturday, I reported on the first Critical Update for Firefox. In addition to being pleased with the rapid response and integrated update notification, I was concerned about the fact that almost no detail was given on the vulnerability, either in the update tool or on any of several Mozilla websites. At the time, I [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-198","post","type-post","status-publish","format-standard","hentry","category-browsers"],"_links":{"self":[{"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/posts\/198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/comments?post=198"}],"version-history":[{"count":0,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/posts\/198\/revisions"}],"wp:attachment":[{"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/media?parent=198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/categories?post=198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jclark.org\/weblog\/wp-json\/wp\/v2\/tags?post=198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}