<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/10208/FireFox_Mobile_Security_News</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2009, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Mon, 06 Jul 2009 19:36:54 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>Yeah...</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>At least this doesn't work in Opera, this I can tell!<br />
<a href="http://secunia.com/mozilla_products_arbitrary_memory_exposure_test/" rel="nofollow">http://secunia.com/mozilla_products_arbitrary_memory_exposure_test/</a></description>
			<pubDate>Tue, 05 Apr 2005 18:42:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Fixed for 1.0.3 (presently RC)</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=288688" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=288688</a></description>
			<pubDate>Tue, 05 Apr 2005 18:48:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>fixed in 1.0.3</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>Firefox 1.0.3 which is released in a few hours fixes this problem (as well as an installer problem for the windows version and a couple of crasher bugs)</description>
			<pubDate>Tue, 05 Apr 2005 18:49:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Would someone explain....</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>In the example it looks like the random memory heap data is only visible locally. <br />
<br />
Is it possible for a remote computer to see it, or is this like the 'contents of your c drive' thing some sites used to try to con windows users with? (It just opened a local window listing c:, there was no remote access.)</description>
			<pubDate>Tue, 05 Apr 2005 19:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>@human</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>A site could read the memory and redirect to a page which logs such memory.  It could even try to filter out readable strings first.  This is a BAD vulnerability.</description>
			<pubDate>Tue, 05 Apr 2005 19:54:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>re: @human</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>and will be fixed shortly...</description>
			<pubDate>Tue, 05 Apr 2005 20:44:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>I'm sick of OSS security flaws...</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>Not only is Firefox beginning to show it weaknesses, but Linux has a ton of vulnerabilities.  See here:<br />
<br />
<a href="http://secunia.com/advisories/" rel="nofollow">http://secunia.com/advisories/</a><br />
<a href="http://www.securityfocus.com/bid" rel="nofollow">http://www.securityfocus.com/bid</a><br />
<br />
I stopped using Linux when I realized it was less secure than Windows.</description>
			<pubDate>Tue, 05 Apr 2005 20:53:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE:  I'm sick of OSS security flaws...</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>That seems a little premeture.<br />
<br />
Out of the contents of the first page that you posted, the only one that could possibly effect me was the firefox one, and that appears to be fixed. The rest were for software I don't use. (I'm the only 'local' user on my computer.)<br />
<br />
On the second link, it was a mix of Windows and AIX and all kinds of weird webservery stuff.<br />
<br />
I don't consider myself a computer expert, but I think people should ask themselves - 'What is MY experience with this OS?.' rather than 'What did I read today on the internet?'.</description>
			<pubDate>Tue, 05 Apr 2005 21:18:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>@Dr.BooBooGone</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>I stopped using Linux when I realized it was less secure than Windows.<br />
<br />
Ah, so you switched to FreeBSD, then?</description>
			<pubDate>Tue, 05 Apr 2005 21:21:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>re:I'm sick of OSS security flaws..</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>Not only is Firefox beginning to show it weaknesses, but Linux has a ton of vulnerabilities. See here:<br />
<br />
<a href="http://secunia.com/advisories/" rel="nofollow">http://secunia.com/advisories/</a><br />
<a href="http://www.securityfocus.com/bid" rel="nofollow">http://www.securityfocus.com/bid</a><br />
<br />
I stopped using Linux when I realized it was less secure than Windows.<br />
<br />
Ok Bill G. time to go play somewhere else. Can we say troll?</description>
			<pubDate>Tue, 05 Apr 2005 21:48:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>@historyb</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>Actually, if you look at securityfocus, the Linux kernel alone has somewhere around 23 vulnerabilities in the last week.  Some advisories have multiple, so you have to view them to see how mean those have.</description>
			<pubDate>Tue, 05 Apr 2005 21:58:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>OSS security audit by millions of opensource developers reviewing sources 24/7</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>Fixed on trunk, AVIARY_1_0_1_20050124_BRANCH, and MOZILLA_1_7_BRANCH.<br />
Thanks for the report, I hope that's the last bug from 1997 left ;-).</description>
			<pubDate>Tue, 05 Apr 2005 22:53:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>huh?!?</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>every time i post it goes missing what gives?</description>
			<pubDate>Tue, 05 Apr 2005 23:09:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>I wonder why...</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>...post from Dr.BooBooGone has been moderated down. Moreover, he posted a couple of useful links. His post didn't look offensive in any way nor it looked like a trolling post.<br />
<br />
Or should we ALL agree that Linux is more secure than anything which has been created before?</description>
			<pubDate>Wed, 06 Apr 2005 00:11:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>@The Bitland Prince</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>You only have to look at the OSNews editor profiles to figure out why. All state OSS as an interest but very few (one from memory) says he has experience with Windows</description>
			<pubDate>Wed, 06 Apr 2005 00:18:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>@vcv:</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>Sure, now go look at Security Focus's page for Microsoft, it's just the same. What do we learn from this? A standard install of either Windows or Linux is going to be basically completely vulnerable to local DoS and privilege escalation (which make up a good 90% of the vulnerabilities listed for each, by a casual eyeball), therefore, very important security concept - don't allow remote login (*definitely* not a shell), use strong passwords, don't allow untrusted users. Yes, that's earth-shatteringly new information!<br />
<br />
If you're going to run a system with multiple local users who need to be properly secured, you're going to need to do some _heavy_ security work, no matter what OS you run. If you're not going to run such a system, a lot of the vulnerabilities listed for both products are not going to affect you.</description>
			<pubDate>Wed, 06 Apr 2005 02:00:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Nightly 1.0.3</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>Any nightly build from mozilla has no problems with this leak.</description>
			<pubDate>Wed, 06 Apr 2005 03:44:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>@AdamW</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>I agree completely.  It was just an attempt to more even the playing field in Windows vs. Linux as far as security goes.  Neither has a good track record as far as I'm concerned.</description>
			<pubDate>Wed, 06 Apr 2005 04:25:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Secunia is danish</title>
			<link>http://osnews.com/thread?</link>
			<guid isPermaLink="true">http://osnews.com/thread?</guid>
			<description>Not that its very important, but I was under the impression that Secunia is danish - Or have they been bought up recently?<br />
<br />
From their website:<br />
<br />
Secunia<br />
Toldbodgade 37B<br />
1253 Copenhagen K<br />
Denmark</description>
			<pubDate>Wed, 06 Apr 2005 06:46:00 GMT</pubDate>
			<author>donotreply@osnews.com (Anonymous)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
