upgrade to firefox 2.0.0.9

Bug #160895 reported by FredBezies
4
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Fix Released
High
Alexander Sack
Edgy
Fix Released
High
Alexander Sack
Feisty
Fix Released
High
Alexander Sack
Gutsy
Fix Released
High
Alexander Sack
Hardy
Fix Released
High
Alexander Sack

Bug Description

Binary package hint: firefox

It would be great to have firefox 2.0.0.9 as a security upgrade for Ubuntu gutsy gibbon. 2.0.0.9 was released last week, on 1st november :

http://developer.mozilla.org/devnews/index.php/2007/11/01/firefox-2009-stability-update-now-available-for-download/

And it is not, like for firefox 2.0.0.7 a windows only release.

So, please ? ;)

Thanks a lot !

Revision history for this message
Millard Scott (mnmiscott) wrote : Re: [Bug 160895] upgrade to firefox 2.0.0.9

please take off the bug contact list or let me know what I have to do to get my name off.

Thank you,

----- Original Message ----
From: FredBezies <email address hidden>
To: <email address hidden>
Sent: Thursday, November 8, 2007 2:57:29 AM
Subject: [Bug 160895] upgrade to firefox 2.0.0.9

Public bug reported:

Binary package hint: firefox

It would be great to have firefox 2.0.0.9 as a security upgrade for
Ubuntu gutsy gibbon. 2.0.0.9 was released last week, on 1st november :

http://developer.mozilla.org/devnews/index.php/2007/11/01/firefox-2009
-stability-update-now-available-for-download/

And it is not, like for firefox 2.0.0.7 a windows only release.

So, please ? ;)

Thanks a lot !

** Affects: firefox (Ubuntu)
     Importance: Undecided
         Status: New

--
upgrade to firefox 2.0.0.9
https://bugs.launchpad.net/bugs/160895
You received this bug notification because you are a bug contact for
firefox in ubuntu.

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

Revision history for this message
FredBezies (fredbezies-deactivatedaccount) wrote :

Just log in, go to this bug and click on unsuscribe option.

Revision history for this message
Alexander Sack (asac) wrote :

On Thu, Nov 08, 2007 at 08:57:29AM -0000, FredBezies wrote:
> Public bug reported:
>
> Binary package hint: firefox
>
> It would be great to have firefox 2.0.0.9 as a security upgrade for
> Ubuntu gutsy gibbon. 2.0.0.9 was released last week, on 1st november :

This is not a security update, but _just_ a stability upgrade for
regressions introduced in 2.0.0.8. We will do it anyway next week.

 - Alexander

Changed in firefox:
assignee: nobody → asac
importance: Undecided → High
status: New → In Progress
assignee: nobody → asac
importance: Undecided → High
status: New → In Progress
assignee: nobody → asac
importance: Undecided → High
status: New → In Progress
assignee: nobody → asac
importance: Undecided → High
status: New → In Progress
Revision history for this message
Joe Davison (joesephus) wrote :

Another option is to use Ubuntuzilla. You can find instructions here: http://ubuntuzilla.wiki.sourceforge.net/

Revision history for this message
John Vivirito (gnomefreak) wrote :

Joe please dont advise that on official bugs, it is unsupported by ubuntu and has caused alot issues in past. When we get a few minutes we will get it in gutsy but we have alot of stuff we are working on. We will have it in Gutsy as soon as we can.

Revision history for this message
Swistak (swistakers) wrote :

I'm writing just to remind you, that 2.0.0.9 is still not there

Revision history for this message
Jordi R (jordi1983) wrote :

Maybe we should ask for 2.0.0.10, there is candidate builds in the mozilla ftp.

Revision history for this message
Savvas Radevic (medigeek) wrote :

this was in an earlier version of @risk newsletter:
(November 5th 2007)
@RISK: The Consensus Security Vulnerability Alert Vol. 6 No. 45

(4) HIGH: Mozilla Firefox Arbitrary Script Execution Vulnerability
Affected:
Mozilla Firefox versions 2.0.0.8 and prior

Description: Mozilla Firefox contains a vulnerability in its handling
of JavaScript. A specially crafted web page could bypass domain
restrictions an allow an attacker to execute arbitrary JavaScript in a
security domain different from that in which it was loaded. This could
allow an attacker to alter the user interface or potentially execute
arbitrary code with the privileges of the current user. Some technical
details and a proof-of-concept are available for this vulnerability.
Additionally, technical details may be available via source code
analysis. Other Mozilla products, such as Thunderbird and SeaMonkey may
also be affected.

Status: Mozilla has not confirmed, no updates available.

References:
Posting by The Hacker Webzine
http://www.0x000000.com/index.php?i=465
Proof-of-Concept
http://downloads.securityfocus.com/vulnerabilities/exploits/26283.html
SecurityFocus BID
http://www.securityfocus.com/bid/26283

It's not confirmed though, 2.0.0.9 is just a stability update:
Firefox 2.0.0.9 stability update now available for download

Nevertheless, it's widely used as a default browser, Ubuntu should support a stability update in order to be more efficient.
Or at least put it in backports :)

Revision history for this message
Savvas Radevic (medigeek) wrote :

I think that this bug report is obsolete as of today
$ apt-get policy firefox

firefox:
  Installed: 2.0.0.10+2nobinonly-0ubuntu1.7.10.1
  Candidate: 2.0.0.10+2nobinonly-0ubuntu1.7.10.1
  Version table:
 *** 2.0.0.10+2nobinonly-0ubuntu1.7.10.1 0
        500 http://security.ubuntu.com gutsy-security/main Packages
        100 /var/lib/dpkg/status
     2.0.0.8+2nobinonly-0ubuntu1 0
        500 http://uk.archive.ubuntu.com gutsy-updates/main Packages
     2.0.0.6+2nobinonly-0ubuntu1 0
        500 http://uk.archive.ubuntu.com gutsy/main Packages

https://launchpad.net/ubuntu/gutsy/+source/firefox/2.0.0.10+2nobinonly-0ubuntu1.7.10.1

Alexander Sack (asac)
Changed in firefox:
status: In Progress → Fix Released
status: In Progress → Fix Released
status: In Progress → Fix Released
status: In Progress → Fix Released
Revision history for this message
Ramon (ramonftmx) wrote :

unsubscribe

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.