Live data from Hacker News

Mozilla patches Firefox zero-day abused in the wild

zdnet.com

21–30 of 111 posts

Re: Mozilla patches Firefox zero-day abused in the wild

#21

https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 I find it really gross that they do not allow others to access it. This behavior damages the forks.

The source code for the fix is public. Presumably the bug report includes working exploit code. I don't see how this is "damaging" for forks.

Re: Mozilla patches Firefox zero-day abused in the wild

#22
post #8

Earlier quoted context omitted.

True they could have been clearer on the versions affected, but tbh you should keep with the latest supported anyway. Security bug reports are often restricted for some time after a new release to help prevent reverse engineering to find the bug.

Please do not assume people are not running current release just because they are lazy and have not upgraded. The user experience was degraded at FF57 for many individuals who need extensions that will not work with ff>56 or that developers have abandoned out of frustration with Mozilla. When all the extensions I find necessary are functional (or with suitable replacements) I will switch.

Firefox 56 is unlikely to ever receive security patches every again. You are incredibly vulnerable by staying behind.

Re: Mozilla patches Firefox zero-day abused in the wild

#23
Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched...). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf

Re: Mozilla patches Firefox zero-day abused in the wild

#24
post #4

Really unhappy with Mozilla. Does this effect all versions of Firefox? Quantum only? The bug report itself is not viewable publicly either.

True they could have been clearer on the versions affected, but tbh you should keep with the latest supported anyway. Security bug reports are often restricted for some time after a new release to help prevent reverse engineering to find the bug.

Mozilla was, Zdnet was not. https://www.mozilla.org/en-US/security/advisories/mfsa2019-1...

Re: Mozilla patches Firefox zero-day abused in the wild

#29

https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 I find it really gross that they do not allow others to access it. This behavior damages the forks.

Mozilla can still give access for the developers of forks without opening it to the public before they (and the forks!) have managed to rollout a full update.

Re: Mozilla patches Firefox zero-day abused in the wild

#30

https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 I find it really gross that they do not allow others to access it. This behavior damages the forks.

Mozilla can still give access for the developers of forks without opening it to the public before they (and the forks!) have managed to rollout a full update.

Anyone can run a fork though, I right now might be running my personal fork. This is part of the point of free software.

Plus, you assume that the select few developers that are given the exploit information are trustworthy. The exploit being public from the first day is better than if even a single developer is untrustworthy or compromised.

Post reply on HN