Firefox 1.0.7 Fixes Several Critical Vulnerabilities; Recommended Upgrade火狐1.0.7修补程序的几个关键的脆弱性;建议升级
Firefox 1.0.7 is a security and stability release.火狐1.0.7是一个安全和稳定的释放。 It is strongly recommend that all users upgrade to this latest version.这是强烈建议所有用户升级到这个最新的版本。
This version includes several security and stability fixes, including a fix for a reported buffer overflow vulnerability and a fix for a Linux shell command vulnerability.此版本包括几个安全与稳定的修复,包括修复据报道,缓冲区溢出漏洞并修复了一个为Linux的Shell命令的脆弱性。 Details below.下面详细说明。
Specific changes in Firefox 1.0.7具体变化在Firefox 1.0.7
- Fix for a potential buffer overflow vulnerability when loading a hostname with all soft-hyphens修复一个潜在的缓冲区溢出漏洞,当加载的主机与所有软连字符
- Fix to prevent URLs passed from external programs from being parsed by the shell (Linux only)修复程序,以防止网址,通过从外部程序被解析,由壳牌( Linux的唯一)
- Fix to prevent a crash when loading a Proxy Auto-Config (PAC) script that uses an “eval” statement修复程序,以防止碰撞时,加载代理自动配置(委员会)的脚本使用“ eval ”声明
- Fix to restore
InstallTrigger.getVersion()for Extension authors修复恢复installtrigger.getversion ( )为扩展作者 - Other stability and security fixes其他的稳定性和安全性修正 : :
- MFSA 2005-59 (High) mfsa 2005-59 (高) - Command-line handling on Linux allows shell execution -命令行处理L inux的允许壳牌执行
- MFSA 2005-58 (Critical) mfsa 2005-58 (关键) - Firefox 1.0.7 / Mozilla Suite 1.7.12 Vulnerability Fixes -火狐1 .0.7/对M ozillaS uite1 .7.12漏洞修复
- MFSA 2005-57 (Critical) mfsa 2005-57 (关键) - IDN heap overrun using soft-hyphens -印度尼西亚的堆积满溢使用软连字符
You can download您也可以下载 Firefox 1.0.7火狐1.0.7 here这里 . 。
The known issues are: 已知的问题是:
All Systems 所有系统
* Prior to installing Firefox 1.0.7, please ensure that the directory you’ve chosen to install into is clean and doesn’t contain any previous Firefox installations. *之前,必须先安装的Firefox 1.0.7 ,请确保该目录您选择安装到的是清洁和不包含任何以前的Firefox设施。
* If you install Firefox on a multi-user system in an area in which there is restricted access privileges, you must run Firefox as a user with access to that location upon installation so that all initial startup files are generated. *如果您安装了Firefox的一个多用户系统在在这方面是有限制的存取权限,则必须运行Firefox作为一个用户访问到该位置后,安装,使所有的初步启动文件所产生的。 If this is not done, when a user without write access to the install location attempts to start Firefox, they will not have sufficient privileges to allow Firefox to generate the initial startup files it needs to.如果不这样做,当用户没有写入权限的安装位置的企图开始Firefox的,他们不会有足够的特权,让Firefox的产生最初的启动文件,它需要。
* When upgrading, all your Extensions and Themes will be disabled. *升级时,您所有的扩展和主题将被禁用。 This is not an issue, but it may appear to be one (hence its listing here).这是不是一个问题,但它可能显示为1 (因此其港上市) 。 For rationale, see “Extension and Themes” above.为理由,见“扩展和主题”以上。
* Software Update does not request proxy authentication and will fail if you are behind a proxy server. *软件更新不要求代理身份验证和会失败,如果你是背后的代理服务器。 (bug) The workaround is to visit a web page in the browser and log in to the proxy server and then perform Software Update. (错误)替代是访问一个网页在浏览器并登录到代理服务器,然后执行软件更新。
* Software Update will not work if Firefox is installed to a location that you do not have write access to, since Software Update needs to replace or create files in this location. *软件更新将不会工作,如果Firefox是安装到某个位置,你没有写入权限,因为软件更新的需要,以取代或建立档案,在这个位置。
* The Help documentation refers to “Single Window Mode” options regarding “Force links opened in new windows to open in [New Tab, Same Tab].” This function was disabled at the last minute due to problems we were experiencing with it, so ignore this section of Help. *帮助文档是指“单一窗口模式”选项就“武力打开链接在新窗口打开在[新标签,同时标签] ”这个功能被停用,在最后一分钟,由于问题,我们正在经历有了它,因此,忽略这一段的帮助。 To re-enable the Single Window Mode options (at your own risk - there may be crashes), use the Configuration Console (accessed by entering “about:config” in the Location bar and pressing Enter) to set browser.tabs.showSingleWindowModePrefs to true.重新启用单一窗口模式选项(您自己承担风险-有可能崩溃) ,使用配置控制台(存取进入“关于:配置” ,在位置的酒吧和紧迫进入)设置,以b rowser.tabs.showsinglewindowmodeprefs正确的。Windows 在Windows
* On Windows 2000 systems, some users may experience a crash on exit of the browser after viewing a page that calls the Windows Media Player 9 plug-in. *对Windows 2000系统,有些用户可能会遇到撞车就退出浏览器后,查看网页调用Windows Media Player 9的外挂程式。 If you experience this, make sure you are using the newest version of the Java plug-in, greater than Java 1.5.如果您的经验,这一点,请确保您使用最新版本的Java插件中,大于1.5的Java 。 Older versions of the Java plug-in may conflict with Windows Media Player 9 in Firefox.旧版本的Java插件在5月的冲突与Windows Media Player 9月在Firefox 。
* When installing as a restricted access user on a shared machine into a location that you can write to, there may still be negative side effects (default browser/other keys not being set correctly). *安装时,作为一个限制访问的用户在一个共用的机器成为一个位置,你可以写,可能仍有消极的副作用(默认的浏览器/其他键没有被正确设置) 。 The browser should still function however.浏览器仍应功能,但。 When installing as a restricted access user do not attempt to install over an installation in a restricted-access/shared location as this may destroy that installation.安装时,作为一个限制访问的用户不要尝试安装了一个安装在一个restricted-access/shared位置,因为这可能破坏这一安装。
* Firefox may hang when closing after viewing a PDF file in some older versions of the Adobe Acrobat Reader plug in. If you experience this, make sure you are using the newest version of the plug in. * Firefox的可能会挂起时,闭幕后,检视PDF档案在一些旧版本的Adobe Acrobat Reader插件英寸如果您的经验,这一点,请确保您使用最新版本的插件英寸
* On Windows 98 and Windows ME systems, the Application icon may appear as a Windows icon. *在Windows 98和Windows Me系统,应用程序图标可能会出现一个Windows图标。Mac OS X 在Mac OS X
* Do NOT run Firefox from the Disk Image! *不要运行的Firefox从磁盘的形象! - doing this will cause an infinite restart loop (the symptom of which is a Firefox icon that bounces briefly in the Dock then disappears and reappears, bounces and disappears, over and over). -这样做将导致一个无限重新启动回路(症状,这是一个F irefox的图标,跳出简单的被告席上,然后消失和重新出现,跳出和消失,超过以上) 。 To break Firefox out of this loop, open a Terminal and type “killall firefox-bin” and press enter.打破Firefox的走出这个循环,打开一个终端并键入“ killall的Firefox斌”并按下Enter 。 Install Firefox to a location you have write access to and try again.安装Firefox的某个位置,你有写入权限,然后再试一次。 When installing on a multi- user limited access system, install it into a shared location as administrator, run it once and then all users should be able to access it.安装时,一个多用户有限的准入制度,它安装到一个共享的位置,作为管理员,运行它一次,然后所有用户都应该能够访问它。
* If Firefox does not display a browser window, quit Firefox using Cmd+Q and open ~/Library/Application Support/Firefox/Profiles/ *如果Firefox不显示浏览器窗口,退出Firefox的使用cmd + Q和开放〜 /资源库/应用支持/火狐/概况/.default/ and remove localstore.rdf. 。默认/删除localstore.rdf 。 Restart Firefox.重新启动Firefox 。 Any toolbar customizations you have made or window placement will be lost任何工具栏自定义您已作出的或在窗口的位置将丢失 Linux and Unix systems Linux和Unix系统
* If Firefox is installed to a location with spaces in the path, Firefox may not be able to set itself as Default browser and may keep prompting at startup. *如果Firefox是安装到某个位置,与位在道路上, Firefox的未必能订定本身的作为默认浏览器,并可能继续促使在启动。 The work around is to install into a path without spaces.周围的工作是安装到路径没有空格。
* GNOME integration does not work properly with Fedora Core 3. * GNOME的整合工作不妥善的Fedora Core 3 。 Users of Fedora Core 3 will need to download and install linc-1.0.3-3.1.i386.rpm.用户的Fedora Core 3 ,将需要下载并安装linc - 1.0.3 - 3.1.i386.rpm 。 After installing the RPM, perform the following command in the directory you installed Firefox into (you will need write permission):在安装RPM的,请执行下列命令在目录中你安装过Firefox的进入(你需要写权限) :touch .autoreg触摸。 autoreg
The next time you start Firefox, GNOME integration should be functional.当您下一次启动Firefox时, GNOME的一体化应功能。
Web Page Rendering 网页渲染
* Firefox is powered by the same Gecko layout engine as other Mozilla software. * Firefox是由相同的Gecko版面引擎作为其他Mozilla软件。 If you encounter a problem with a website that does not correctly display then it is usually a problem with Gecko, not Firefox itself.如果您遇到的问题与一个网站,这并不正确显示的话,通常是一个问题与壁虎,而不是Firefox的本身。 Such problems should be reported in the Core product (not the Firefox product) in Bugzilla.这些问题,应当报在核心产品(而不是Firefox的产品)在bugzilla 。 If you are technically minded, try and create a reduced test case and this will help get your bug more attention.如果您是在技术上的头脑,尝试创造一个减少测试案例,这将有助于让您的错误更多的关注。
For additional issues, FAQs, Tips and Tricks plus general Firefox help be sure to check out Firefox Help and the Firefox forums hosted by MozillaZine.为额外的问题,常见问题解答,技巧和窍门,另加一般Firefox的帮助,请务必检查出Firefox的帮助和Firefox的论坛主办的mozillazine 。
The Configuration Console (accessed by entering “about:config” in the Location bar and pressing Enter) gives advanced/experienced users direct control over Firefox’s preferences.配置控制台(存取进入“关于:配置” ,在位置的酒吧和紧迫的输入) ,让先进的/有经验的用户直接控制Firefox的偏好。 This system is for use by people who know what they are doing only, by changing a value incorrectly you may damage or destroy your Firefox installation!这个系统是使用的人谁知道自己在做什么,只有通过改变一个值不正确,你可能会损害或破坏您的Firefox安装! Look to Help sites for handy preferences to tweak to customize Firefox further.看看,以帮助网站为方便偏好来调整自定义Firefox的进一步。
Hat-tip: James Huff @帽子提示:詹姆斯吞吐@ MacManx macmanx
Filed under提起下 Computer Security计算机安全 , , Headline News头条新闻 , , Web网页 | |
| |
RSS 2.0 2.0 | |
Trackback Trackback跟踪 this Article |此文章|
Email this Article电子邮件此文章
You may also like to read您也可以想读 |




October 28th, 2006 at 12:47 pm 2006年10月28日在下午12时47分
JAVA SOFTWARE application is not working after installing Internet Explorer 7 ? Java软件的应用是没有工作后,安装Internet Explorer 7 ?