<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Mozilla Firefox Security Bug Not Quite Fixed</title>
	<atom:link href="http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/feed/" rel="self" type="application/rss+xml" />
	<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/</link>
	<description>Technology News</description>
	<lastBuildDate>Sat, 21 Nov 2009 21:30:02 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Ryan</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-73193</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Mon, 08 Jan 2007 17:15:25 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-73193</guid>
		<description>I had completely forgotten about this, but the original bug has been fixed as the website says. My Firefox 2.0.0.1 didn&#039;t crash on the first one that it mentions but the other one that it says hasn&#039;t been fixed.</description>
		<content:encoded><![CDATA[<p>I had completely forgotten about this, but the original bug has been fixed as the website says. My Firefox 2.0.0.1 didn&#8217;t crash on the first one that it mentions but the other one that it says hasn&#8217;t been fixed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SLA</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-73084</link>
		<dc:creator>SLA</dc:creator>
		<pubDate>Mon, 08 Jan 2007 09:45:22 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-73084</guid>
		<description>Still works with Firefox 2.0.1. :(</description>
		<content:encoded><![CDATA[<p>Still works with Firefox 2.0.1. <img src='http://cybernetnews.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SLA</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-28882</link>
		<dc:creator>SLA</dc:creator>
		<pubDate>Wed, 25 Oct 2006 11:52:22 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-28882</guid>
		<description>There is NO software which doesn&#039;t need patching in the whole world. Every software needs to be patched sooner or later. This is absolutely normal. All humans&#039; creations are buggy :)</description>
		<content:encoded><![CDATA[<p>There is NO software which doesn&#8217;t need patching in the whole world. Every software needs to be patched sooner or later. This is absolutely normal. All humans&#8217; creations are buggy <img src='http://cybernetnews.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hansen</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-28871</link>
		<dc:creator>Hansen</dc:creator>
		<pubDate>Wed, 25 Oct 2006 07:57:54 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-28871</guid>
		<description>Hmmm, I don&#039;t really know why, but surprisingly it didn&#039;t crash my firefox v1.0.7 under Fedora Core 3!</description>
		<content:encoded><![CDATA[<p>Hmmm, I don&#8217;t really know why, but surprisingly it didn&#8217;t crash my firefox v1.0.7 under Fedora Core 3!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: netster007x</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-28861</link>
		<dc:creator>netster007x</dc:creator>
		<pubDate>Wed, 25 Oct 2006 05:27:26 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-28861</guid>
		<description>I&#039;ve got noscript as well, so to test the site I reluctantly temporarily enabled javascript and yup, crashed as advertised.  This really surprises me, and I bet it&#039;ll be fixed soon!  Kinda sad, though, that this brand new release already needs patching.

Fx2</description>
		<content:encoded><![CDATA[<p>I&#8217;ve got noscript as well, so to test the site I reluctantly temporarily enabled javascript and yup, crashed as advertised.  This really surprises me, and I bet it&#8217;ll be fixed soon!  Kinda sad, though, that this brand new release already needs patching.</p>
<p>Fx2</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SLA</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-28804</link>
		<dc:creator>SLA</dc:creator>
		<pubDate>Tue, 24 Oct 2006 19:08:48 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-28804</guid>
		<description>&lt;strong&gt;Firefox 3.0 alpha (20061011)&lt;/strong&gt; - crashed in 1 second.
&lt;strong&gt;IE 7.0 Final Release&lt;/strong&gt; - freezes for 5 minutes (eating 50% CPU, and RAM 135MB/5min), then I killed IE7 process.
Opera 9.02 - resisted successfully (with about 30 seconds &quot;wait&quot; mouse pointer).

I&#039;m sure that Mozilla team will fix this VERY soon, and what about Microsoft team? We will have to wait 1 year until IE7 SP1, or 5 years until IE8 ? :)</description>
		<content:encoded><![CDATA[<p><strong>Firefox 3.0 alpha (20061011)</strong> &#8211; crashed in 1 second.<br />
<strong>IE 7.0 Final Release</strong> &#8211; freezes for 5 minutes (eating 50% CPU, and RAM 135MB/5min), then I killed IE7 process.<br />
Opera 9.02 &#8211; resisted successfully (with about 30 seconds &#8220;wait&#8221; mouse pointer).</p>
<p>I&#8217;m sure that Mozilla team will fix this VERY soon, and what about Microsoft team? We will have to wait 1 year until IE7 SP1, or 5 years until IE8 ? <img src='http://cybernetnews.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ajay</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-28801</link>
		<dc:creator>Ajay</dc:creator>
		<pubDate>Tue, 24 Oct 2006 18:43:42 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-28801</guid>
		<description>Crashed IE7 as well.</description>
		<content:encoded><![CDATA[<p>Crashed IE7 as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lewis</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-28800</link>
		<dc:creator>Lewis</dc:creator>
		<pubDate>Tue, 24 Oct 2006 18:38:03 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-28800</guid>
		<description>Crashes MSIE 6 for me.</description>
		<content:encoded><![CDATA[<p>Crashes MSIE 6 for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-28797</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Tue, 24 Oct 2006 18:28:53 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-28797</guid>
		<description>Wrong bug.

The bug causing the crash you see here is at:
https://bugzilla.mozilla.org/show_bug.cgi?id=323394

It is still in a new state with no clear path of how to fix it. As I read this, it isn&#039;t the claimed security hole that the Security Advisory page talks about.

This doesn&#039;t cause any memory corruption, just a stack overflow and the application immediately aborts.

from the comments on the bug:
 ------- Comment #13 From Robert O&#039;Callahan (Novell)  2006-09-11 21:26 PDT  [reply] -------

There is no way to fix this without breaking very deeply nested pages ...
except by rewriting Gecko to avoid the use of recursion. That would take a
while.


------- Comment #14 From Robert O&#039;Callahan (Novell) 2006-09-11 21:27 PDT [reply] -------

I think limiting the depth allowed by the XML parser, just like the HTML parser
does, would be a good start.</description>
		<content:encoded><![CDATA[<p>Wrong bug.</p>
<p>The bug causing the crash you see here is at:<br />
[<a href='https://bugzilla.mozilla.org/show_bug.cgi?id=323394' rel='nofollow'>bugzilla.mozilla.org</a>]</p>
<p>It is still in a new state with no clear path of how to fix it. As I read this, it isn&#8217;t the claimed security hole that the Security Advisory page talks about.</p>
<p>This doesn&#8217;t cause any memory corruption, just a stack overflow and the application immediately aborts.</p>
<p>from the comments on the bug:<br />
 &#8212;&#8212;- Comment #13 From Robert O&#8217;Callahan (Novell)  2006-09-11 21:26 PDT  [reply] &#8212;&#8212;-</p>
<p>There is no way to fix this without breaking very deeply nested pages &#8230;<br />
except by rewriting Gecko to avoid the use of recursion. That would take a<br />
while.</p>
<p>&#8212;&#8212;- Comment #14 From Robert O&#8217;Callahan (Novell) 2006-09-11 21:27 PDT [reply] &#8212;&#8212;-</p>
<p>I think limiting the depth allowed by the XML parser, just like the HTML parser<br />
does, would be a good start.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://cybernetnews.com/mozilla-firefox-security-bug-not-quite-fixed/comment-page-1/#comment-28791</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Tue, 24 Oct 2006 17:40:21 +0000</pubDate>
		<guid isPermaLink="false">http://tech.cybernetnews.com/2006/10/24/mozilla-firefox-security-bug-not-quite-fixed/#comment-28791</guid>
		<description>&lt;div id=&quot;commentquote&quot;&gt;&lt;a href=&quot;#comment-28784&quot;&gt;Dave wrote:&lt;/a&gt;&lt;blockquote&gt;javascript required

so once again, the noscript extension comes in handy&lt;/blockquote&gt;&lt;/div&gt;
Thanks Dave...I forgot to mention that but I added it to the post.

&lt;div id=&quot;commentquote&quot;&gt;&lt;a href=&quot;#comment-28790&quot;&gt;Nate The Great wrote:&lt;/a&gt;&lt;blockquote&gt;That link even pretty much crashed IE7. after it loads it wont respond. ctrl alt delete saves the day again! :)&lt;/blockquote&gt;&lt;/div&gt;
I tried it in IE7 and even though it did run a little sluggish I was still able to close the tab and have it return to normal without restarting the browser.</description>
		<content:encoded><![CDATA[<div id="commentquote"><a href="#comment-28784">Dave wrote:</a><br />
<blockquote>javascript required</p>
<p>so once again, the noscript extension comes in handy</p></blockquote>
</div>
<p>Thanks Dave&#8230;I forgot to mention that but I added it to the post.</p>
<div id="commentquote"><a href="#comment-28790">Nate The Great wrote:</a><br />
<blockquote>That link even pretty much crashed IE7. after it loads it wont respond. ctrl alt delete saves the day again! <img src='http://cybernetnews.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p></blockquote>
</div>
<p>I tried it in IE7 and even though it did run a little sluggish I was still able to close the tab and have it return to normal without restarting the browser.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
