Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Firefox 1.0.7 Fixes Security Glitches

Add as a preferred source on Google

On Wednesday, the Mozilla Foundation released Firefox 1.0.7 for Windows, Mac OS X, and Linux; the new release includes a number of minor changes, but most importantly fixes two potentially serious security issues which have been widely publicized in recent days.

The most-reported problem fixes an issue with Firefox’s International Domain Name (IDN) feature, which enables Mozilla products to display and resolve Internet domain names using international and/or non-Latin character sets. Links pointing to a long domain name composed entirely of dashes could trigger a buffer overflow which (in theory) could have enabled an attacker using a carefully crafted link to execute arbitrary code on a user’s machine. Although there have been no known exploitations of this problem, Mozilla quickly posted information on how to disable IDN while they worked on a solution.

Recommended Videos

A second serious issue potentially enabling malicious URLs to execute shell scripts under Linux is also addressed in the FireFox 1.0.7 release, along with a potential crash using certain Proxy Auto-Config scripts and some bugs with earlier editions of FireFox which were re-introduced with previous 1.0.x security updates.

The Mozilla Foundation encourages all Firefox users to download and install the 1.0.7 update, which is all well and good; however, repeated attempts to download the update from the Mozilla.org site have failed for more than 30 hours, delaying access to (and coverage of) this update. The Mozilla Foundation has been repeatedly asserting that its response to security issues in its products is more rapid than commercial developers like Microsoft, but the speed of a security fix is immaterial if impacted users cannot acquire the update.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Microsoft revamps Windows Insider Program with simpler structure and more user control
I’m glad Microsoft simplified the Insider program - it was overdue
A man sits, using a laptop running the Windows 11 operating system.

Microsoft is rolling out a major overhaul of its Windows Insider Program, aiming to simplify how early Windows features are tested while addressing long-standing user complaints around complexity and control. The update marks one of the biggest structural changes to the program in years, signaling a shift in how Microsoft wants to collaborate with its testing community.

A Simpler Insider Program Built Around Feedback And Control

Read more
Discord users breach access controls to reach Anthropic’s Mythos model
This AI security breach shows why your data still needs protection
Representative Image

A recent security incident involving Anthropic has highlighted just how fragile the safeguards around advanced AI systems can be. A Wired report suggests that a small group of users, operating through private Discord channels, managed to gain unauthorized access to the company’s highly restricted Mythos AI model - an experimental system designed for cybersecurity applications.

A Breach That Exposes Bigger Risks Around AI Control

Read more
I never thought AI would add typos – but it kind of makes sense
“Anti-Grammarly” tool uses AI to make writing imperfect on purpose
AI tool

A new AI tool is flipping one of the oldest rules of digital communication on its head: perfect grammar is no longer the goal. Instead, the latest trend is to make emails look deliberately human - even if that means adding typos.

When AI Starts Making You Sound Less Perfect

Read more