Mozilla rushes Firefox 3.5.1 to address serious vulnerability

By Scott M. Fulton, III | Published July 16, 2009, 1:51 PM


Download Mozilla Firefox 3.5.1 for Windows from Fileforum now.

After yesterday's discovery of a serious security hole left open by Mozilla Firefox's new TraceMonkey JavaScript engine, the organization chose not to wait until next week -- as had been its plan on Tuesday -- to open up availability of its version 3.5.1 bug fix. Instead, the completed build showed up on Mozilla's FTP servers late Thursday morning, although access to that build through HTTP had been sporadic throughout the early afternoon.

Mozilla's intention was to use 3.5.1 as a vehicle for tweaks to TraceMonkey that did not make the final cut when it came time for the organization to finally release version 3.5. Betanews tests to earlier private builds of 3.5.1 showed that some of those tweaks did appear to produce slight speed gains over and above 3.5. What we don't know at the moment is whether all those tweaks actually did make it to the 3.5.1 version that's being made available today. Since the "Shiretoko" developers track will now effectively be shifted to 3.5.2, evidence of which code got the final tweaks may only be determined through testing.

The organization is also going ahead, as planned, with beta tests of a security build for the older Firefox 3 series, to be called 3.0.12. Today's release comes as Opera unveils its public Beta 2 for version 10 of its Web browser, and Google continues fast and furious with another Dev Channel update to Chrome 3, this time as a bug fix for crashes occurring in its V8 JavaScript engine.

Download Mozilla Firefox 3.5.1 for Windows from Fileforum now.

Comments

View comments by with a score of at least

Firefox not being available in 64-bit is not a big deal and seriously give the guys at Mozilla a break. Firefox takes a while to compile and build and they already are building it for 75 languages for 3 different OS's totaling in 225 different complication and builds. Making it available in 64-bit would multiply that number by 2 (450 different builds) and its not worth it because most people would use the 32 bit version anyway because flash wouldn't work with it. So if having Firefox in 64-bit is so important to you download the source code and compile it in 64-bit yourself.

Score: 0

|

Well, it's out now and not only fixes the security vulnerability but a few other things, as well. Hopefully, 3.5.2 will clean up things further so that it will be more stable.

Score: 1

|

* "After yesterday's discovery of a serious security hole left open by Mozilla Firefox's new TraceMonkey JavaScript engine..."

This was not discovered yesterday. It was filed in Bugzilla a week ago on July 9, there was a minimal testcase (showing exactly what caused this) within the day, and the first patch appeared on Monday, July 13. In fact, yesterday, the bug was already closed as "Fixed."

* "...evidence of which code got the final tweaks may only be determined through testing."

Or, you know, you could look at Bugzilla (or the source code or version-control logs) to find out. They aren't secretive about it. :)

* "Instead, the completed build showed up on Mozilla's FTP servers late Thursday morning, although access to that build through HTTP had been sporadic throughout the early afternoon."

It's NOT completed; Mozilla itself says (when you try to navigate to 3.5.1 using the HTTP interface): "Firefox 3.5.1 is coming soon! Thanks for your interest in the upcoming release of Firefox 3.5.1, but there's still a bit more left to do before we're ready. We're asking for our users and fans to be patient and wait until it appears on the official Firefox website before downloading."

So, we can expect it soon--but it's not necessarily finished yet. (There may be final QA testing to ensure no regressions, for example.)

I really don't know where BetaNews gets random information like this and presents it as fact.

Score: 1

|
Below viewing threshold. Show

This site is heavily "funded" by Microsoft so this really should not be a surprise.

Score: -4

|
Below viewing threshold. Show

Source?

Citation?

Nope.

More BS from the fathead...

Score: -4

|

Impressive turnaround time, though the workaround, disabling Tracemonkey, was pretty mild compared to those for other application vulnerabilities. Still, better the devil one knows than those completely unknown:

http://www.blueridgenetw...-2009-protect-antivirus

I'm referring to the attacks on unknown vulnerabilities that should concern us most. Every month there's news for an exploit and/or patch for a popular application. Translation: before that month, every installation of that application was vulnerable to a very serious attack threat.

Score: 0

|

The workaround wasn't even disabling tracemonkey, it was disabling JIT in TraceMonkey, which might simply make some JS execute a bit slower sometimes.

Score: 0

|

...which, of course, is the JIT component of SpiderMonkey. My bad. :) I thought it was a bit more, but it looks like that's all TraceMonkey is at the moment.

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.