Mozilla releases V 1.7.6
p2pnet.net News:- Mozilla has released a new version it says resolves several important security issues.
Among other things it, fixes "Internationalized Domain Name (IDN) homograph spoofing" which "could be used to construct perfect, indistinguishable phishing sites".
- MFSA 2005-29 Internationalized Domain Name (IDN) homograph spoofing
- MFSA 2005-28 Unsafe /tmp/plugtmp directory exploitable to erase user’s files
- MFSA 2005-27 Plugins can be used to load privileged content
- MFSA 2005-26 Cross-site scripting by dropping javascript: link on tab
- MFSA 2005-25 Image drag and drop executable spoofing
- MFSA 2005-24 HTTP auth prompt tab spoofing
- MFSA 2005-23 Download dialog source spoofing
- MFSA 2005-21 Overwrite arbitrary files downloading .lnk twice
- MFSA 2005-20 XSLT can include stylesheets from arbitrary hosts
- MFSA 2005-18 Memory overwrite in string library
- MFSA 2005-17 Install source spoofing with user:pass@host
- MFSA 2005-16 Spoofing download and security dialogs with overlapping windows
- MFSA 2005-15 Heap overflow possible in UTF8 to Unicode conversion
- MFSA 2005-14 SSL "secure site" indicator spoofing
- MFSA 2005-13 Window Injection Spoofing
It’s available here:
(Thanks, Francois)
Something you think we should know? tips[at]p2pnet.net
<—–Go ahead, make my data ! —->






March 22nd, 2005 at 4:10 pm
can’t find it. I can just find the firefox browser on the page. Does anyone know where to get this?
March 22nd, 2005 at 4:27 pm
Mozilla webpage, with latest version:
http://www.mozilla.org/products/mozilla1.x/
Direct DL – Windows, English (11.0MB)
http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.6/mozilla-win32-1.7.6-installer.exe
March 22nd, 2005 at 5:17 pm
Thanks! Downloading it now.