The Quick Firefox Fix Jumps Over the Lazy Weekend

by Kristin Shoemaker - Mar. 30, 2009Comments (3)

Just last Thursday, I wrote a post proclaiming my undying love for how quickly open source projects tend to right themselves when sailing the choppy waters of software vulnerabilities. This time around, a vulnerability had been spotted in Firefox, affecting 3.x releases on all platforms. The fix was scheduled for release sometime this week, in the browser's 3.0.8 version.

Firefox 3.0.8 made an early arrival, however, and was officially released Friday afternoon (at 3:45 PST). For those keeping score, this was roughly two days after one of the vulnerabilities it patches was discovered.

The 3.0.8 release notes indicate that two security issues have been addressed with this update, and some outstanding bugs (a few unrelated to these vulnerabilities) have been fixed.

Though the update was released Friday, the Mozilla team reminds Firefox users that it can take up to 48 hours to receive the update through the browser (case in point: my Ubuntu laptop received this update early Monday morning). Mozilla also reminds users that the update can be pushed to their local machines manually by going to the Help menu and clicking "Check for Updates." All Firefox users are urged to update their browsers as soon as possible.

Bugs and vulnerabilities are inevitable, but they don't have to be completely unnerving. A project's quick response and decisive action in the face of vulnerabilities often leaves users feeling quite secure. Cheers to the Firefox team for its quick reaction and detailed communication surrounding the vulnerabilities.



Julio Dominguez uses OStatic to support Open Source, ask and answer questions and stay informed. What about you?



3 Comments
 

The only reason why security vulnerabilities in some open source projects can be patched so quickly is that no testing needs to be done to see how other products might be affected. Microsoft or Apple or IBM must test security patches for any particular product against how it might affect other products in their portfolio. Mozilla does not (and has no way of doing so).


0 Votes

I don't think your argument is any good, a BROWSER bug fix should have no impact on other programs whatsoever, that is, if you did not integrate the whole shebang..


0 Votes

I don't think your argument is any good, a BROWSER bug fix should have no impact on other programs whatsoever, that is, if you did not integrate the whole shebang..


0 Votes
Share Your Comments

If you are a member, to have your comment attributed to you. If you are not yet a member, Join OStatic and help the Open Source community by sharing your thoughts, answering user questions and providing reviews and alternatives for projects.