Firefox 16 is retired due to a security problem

Just a couple of days ago the version Firefox 16, and today I find out by Engadget that it was withdrawn from Mozilla FTP for a serious security problem.

As they tell us in EngadgetApparently this vulnerability allowed an attacker, through a malicious website, to access the history of URLs visited by a user, thus making visible both the pages that we have seen in our browser and some parameters that we have used to do so.

Therefore, it is recommended to make a downgrade to version 15.0.1 which is currently the last stable one.

In particular there is something that I do not understand. If version 16 has this problem, does the Aurora and Nightly versions of the channels also carry it with them? I am using version 16 in particular and I am sure that we will have an update shortly that corrects this error.


Leave a Comment

Your email address will not be published. Required fields are marked with *

*

*

  1. Responsible for the data: Miguel Ángel Gatón
  2. Purpose of the data: Control SPAM, comment management.
  3. Legitimation: Your consent
  4. Communication of the data: The data will not be communicated to third parties except by legal obligation.
  5. Data storage: Database hosted by Occentus Networks (EU)
  6. Rights: At any time you can limit, recover and delete your information.

  1.   Rla said

    Maybe that's why it didn't pass testing in Arch?

    1.    City said

      Exactly and I impacted because it was not in arch yet, I had only updated in my debian

      1.    DanielC said

        Whoosh in all the mouth on Debian stability !! : /

        1.    elav said

          At what point did Firefox 16 enter Debian that I didn't know about?

          1.    sieg84 said

            with the majority of readers using debian maybe they thought that firefox is in the debian repositories, understandable error, don't you think?

    2.    Rla said

      And a day after the fix, it is now available in the Arch stable repo.

  2.   lithos523 said

    Too much rush.
    In no time we have gone from version 3.6 to 16.
    Better not run so much and check a little more.

  3.   elynx said

    They go ahead just by being in a certain way more "forward" than the others and look here at the mishaps, always with new versions and they don't pay attention to how stable it is, all quickly, that has been the only thing that I have never liked of Firefox!

    Regards!

    1.    Max Steel said

      What never? If it's something they haven't always done. If they were going step by step, people complained (as it was until 3.6 - 4) and now they complain that it is going fast.

  4.   proper said

    Luckily I don't have versionitis xD

  5.   diazepam said
    1.    elav said

      Mm, but they still haven't warned on the official site .. weird 😀

      1.    diazepam said

        Update(Oct 11, 2012)
        An update to Firefox for Windows, Mac and Linux was released at 12pm PT on Oct 11. Users will be automatically updated and new downloads via http://www.mozilla.org/firefox/new/ will receive the updated version.
        A fix for the Android version of Firefox was released at 9pm PT on Oct 10.

        https://blog.mozilla.org/security/2012/10/10/security-vulnerability-in-firefox-16/

  6.   Ph0eNix said

    Version 16.0.1 is now available, it is already available in the repositories and on the official website.

  7.   milky28 said

    well it's strange to my archlinux does not even inform me to update 16 haha ​​I will know why it will be

  8.   eeefece said

    And is there a way to, for example ... stay on version 10ESR?

    1.    Anonymous said

      Since Ubuntu has PPAs for stable releases and for betas, you should most likely have one for the long support channel that companies use and not have to manually uninstall and install. For Debian, both the ESR and the normal ones are in the repositories and backports, just remember that you will only receive important security updates but not new features and that in November Firefox 17 will be released, which is also ESR where then both versions will upload to the same number (you would still update again in whatever stable version you are) but it would help you to keep from 17 to 24.

    2.    sieg84 said

      There should be a repo, at least in openSUSE in the mozilla repo you have the FireFox ESR option, which by the way 17 will be the next ESR.
      Mageia keeps FireFox ESR as the default version.

  9.   Leo said

    What a downturn, and I'm happy to update.
    Best use KONQUEROR 🙂 🙂

  10.   Ernest Flores said

    Yesterday I just downloaded the update to Firefox 16, after the restart my browser crashed and no matter how hard I tried to access the internet I could not access, then I tried to browse Epyphany and after accessing it also crashed.
    I currently use Ubuntu 12.04 Unity. I will try to see if today through the Ubuntu update system the Firefox problem is already corrected

  11.   veronicab said

    Good morning,
    This is the third day that I have tried to fix my problem with Thunderbird 16.0.1 and outgoing mail server settings, to no avail. I use Ubuntu 12.04.
    I clarify that I can receive but not send.
    Impossible to get help from my server which is Speedy.com.ar because they say they don't have support for this version of Thunderbird.
    Please, do I need to indicate, if possible, how I should configure my account for outgoing mail.
    Currently and as I always have it is: mail.speedy.com.ar for SMTP.
    If you need any more information, please ask me.
    I no longer know where to turn. I have written to Hispanic Mozilla and other places on the web that discuss Thunderbird, but have come to nothing.
    From already thank you very much.

    regards

    1.    elav said

      And if you put smtp.speedy.com.ar?

      1.    veronicab said

        Thanks for responding.

        What happens is that it is mail.speedy.com.ar confirmed by them.
        However I will test your suggestion and report back.

        regards

  12.   veronicab said

    Hello again,

    There's nothing to do.
    I am trying to contact the server again.
    So far I couldn't.
    If I get to solve, notice.

    regards

    1.    KZKG ^ Gaara said

      Hello
      I have tried both with mail…. as with smtp…. and it seems to work, that is, it exists as such. My question is, what is the problem specifically? and what do we owe this for?

      In other words, can you download or view your mail by IMAP or POP3 without problems? Only have problems sending emails (SMTP)?
      This since when is giving you problems.

      regards

      1.    veronicab said

        Hello,
        Thank you very much for answering.
        I can download the emails without problems but I can't send.
        I tried both smtp or mail.speedy.com.ar which is what corresponds, since yesterday I contacted Speedy (finally) and they confirmed that address.
        This happens to me only with Thunderbird in Ubuntu, since in Windows there are no problems, which is why it must be a problem with this version of Th.
        I'll explain the process a bit.
        I had a lot of problems with the files as I was constantly throwing errors and at every startup or reboot I would test the disk for errors. I then thought of reinstalling Ubuntu 12.04 but it did not allow me to back up my email data. The only thing I could do was copy my bookmarks onto a CD. In fact I already recovered them and they are in Firefox.
        I reinstalled then, being careful not to check the formatting box for / home, despite which it formatted me the same. Therefore I lost everything from my home.
        Thanks to the help of Ubuntu-Guide and using Photorec, I recovered many folders, but I still don't know how to put everything in its place.
        I opened some with the extension .txt and apparently there are emails too.
        The problem then started when I set up my account again and I can't find out where the error is.
        Appreciates comments.
        regards

        1.    KZKG ^ Gaara said

          Hello
          Look, the most immediate thing I can think of is that you check the SMTP settings on Windows, and the SMTP settings on Linux. That is, in outgoing server (SMTP) in Thunderbird in Windows (which is where it works well for you) you must have the connection port set (surely port 25), as well as you must have some security configuration set, regarding password, or something like that.

          The idea is that you compare those boxes, those Thunderbird configurations in Windows with Thunderbird in Ubuntu 😉
          And so we will see if there is something different.

          Do you understand or did I complicate a lot? 😀

          I haven't used Ubuntu for a long time, but you don't have to format / home if you didn't check that box when installing 🙁

          Greetings and good luck 😉

          1.    veronicab said

            Hello again 🙂

            I'm already going crazy with this 🙁
            In Windows I don't have Th, I have Outlook Express and I just saw the settings.
            It is practically the same that I have in Th. I say practically because they differ a bit but basically: incoming mail pop.speedy.com.ar and outgoing mail: mail.speedy.com.ar. No strong password.
            Of course, it says that my server requires authentication (use the same as in incoming mail) I do not know what it is because it does not appear.
            Ports, the same: 25 and 110.

            I repeat, I think it is a problem with this version of Th.
            I ask: if I downgrade to a previous version, will I lose the emails again?

            Thanks for your trouble.

            regards

            1.    KZKG ^ Gaara said

              Hello again 🙂
              Where it says that authentication is required, don't worry ... it will use the password you sent when doing POP 😉

              Make sure you have that in Thunderbird ... and since we are, the most important thing and I had not asked you yet LOL !!, what is the specific error that Thunderbird shows you?

              Doing a nop downgrade will not delete any email, but first let's try to solve the problem with this version of Thunderbird and if we don't succeed, we will downgrade.

              regards


            2.    veronicab said

              Hi (to change a bit) haha

              What he answers me is this:

              Sending of message failed.
              Please verify that your Mail & Newsgroups account settings are correct and try again.

              That is…

              Cheers:-)


            3.    KZKG ^ Gaara said

              sup (whats up shortcut) hahaha

              mmm do you need to configure a proxy or something like that in your Thunderbird? is that, I am running out of ideas, I am not in front of your PC so no way, I walk with my hands tied haha.

              Let's try to downgrade 🙂

              Uninstall that Thunderbird, and look in / var / cache / apt / archives / if you don't have the .deb of the previous version, if it's there you double-click it and that's it, the installation wizard should open for you

              If you cannot find the file, let me know to search for it on the internet myself. By the way, which version of Thunderbird do you have right now, and which one do you want to install?

              regards


            4.    veronicab said

              Hm how strange that sup, sounds like soup to me haha

              Well, answering your question:

              I don't use proxy.
              I don't have the previous version in / var / cache / apt / archives / 15.
              I currently have 16.0.1

              I ask you: if I uninstall Thunderbird, Firefox remains untouched, right?
              Because the only thing I need is that Firefox also be uninstalled.

              Thank you


            5.    KZKG ^ Gaara said

              hahahahaha yes, 'sup' is like abbreviating 'you' to just 'u' and even more ... mmm neighborhood, or something like that LOL !.

              If you remove Thunderbird nothing happens to Firefox, they are two different programs 😉

              About Thunderbird 15 in .DEB I'm still looking for it 🙁…
              Meanwhile download this one that I leave below, unzip it, and double-click the executable that is thunderbird:
              http://download.cdn.mozilla.net/pub/mozilla.org/thunderbird/releases/15.0/linux-i686/es-ES/thunderbird-15.0.tar.bz2

              However, I keep looking for 15 in .DEB, it is that in the Ubuntu repos there is Thunderbird 11, and then it goes to 16 ...

              regards


            6.    veronicab said

              Jelou, read Hello, haha

              One question: with the emails that I currently have in this version, nothing happens or do I have to export them?

              thanks


          2.    KZKG ^ Gaara said

            Sorry for the delay, my internet doesn't help me haha.
            Here's Thunderbird 15 in .DEB: http://ftp.desdelinux.net/thunderbird_15.0+build1-0ubuntu0.12.04.1_i386.deb

            And nope, you shouldn't have problems with emails 🙂
            Anyway, for your peace of mind, if you want to export them 😀

            1.    veronicab said

              Thank you very much KZ,
              I just uploaded my mails to Ubuntuone.
              I remembered that I had uploaded some things and I find myself with the (pleasant) surprise that I had uploaded some files that I regretted having lost 🙂

              I appreciate your help and I will tell you what happened with the downgrade.

              see you later 🙂


            2.    veronicab said

              Dear User,
              The version you got me is BETA.
              I'll see if I can find a final version.

              I warn you

              regards


            3.    KZKG ^ Gaara said

              Don't worry about it, it's Beta but it works as stable as any 😉
              You can still try the previous one (.tar.bz2), unzip it, open the executable (thunderbird) and it should open without problems, with all your emails and everything.

              We are here to help do not worry 🙂

              regards


            4.    veronicab said

              Hi KZ,
              A good one among so many tribulations.
              I finally discovered, Google through, the way to fix the blessed mail.
              The solution? Delete the account.
              So I first installed version 16.0, not 0.1 which had brought me problems and then I deleted the account and let Th automatically configure a new one. Now I can receive and send without problems 😀

              Speaking of unzipping. I had downloaded the tar.bz2 version and by googling I found out that to decompress it was necessary to put the command: tar xjvf (file) .tar.bz2, but the order was rejected several times. He spoke something of child and that there was no file or directory.
              Can you please clarify how is the decompression process?

              Thanks and regards 🙂


            5.    KZKG ^ Gaara said

              Hello, how are you?
              I've never really been a fan of deleting accounts and creating them again, it's like admitting that the program beat me HAHAHA.

              To unzip, it's as simple as right-clicking on the file, and you should see the option to unzip it right there 😀
              However, if you want to learn how to do it by commands, read this post: https://blog.desdelinux.net/con-el-terminal-comprimir-descomprimir-archivos/

              regards (I.e.


            6.    veronicab said

              Hi KZ,

              Well if I didn't delete the account it would never have worked because the SMTP was not recognized. In this case I make the program Catalan whistle. What matters is that now it works 🙂

              Yes, I wanted to do it by command, so thanks for the link.

              regards


            7.    KZKG ^ Gaara said

              haha ok, the important thing is that you solved the problem 😀
              My apologies for in the end wasting your time and not having helped you 🙁

              regards

              PS: hahaha congratulations from the heart, congratulations for wanting to do things by command, that is a quality that few have 😀


            8.    veronicab said

              Don't say you didn't help me. Just by answering me and throwing me some ideas, you have already fulfilled.
              Don't congratulate me so much because deep down I'm afraid of the blessed commands but I can't completely close my eyes and think that I'm never going to use them 😀
              Thanks for the link to the commands.

              It will be up to any time you are bothered for a question 🙂

              veronicab


            9.    KZKG ^ Gaara said

              Well I am satisfied then 😀
              Nah do not be afraid of the commands, believe me they are your best friend, because they do exactly what you tell them to do haha, here are some posts that could help you:
              https://blog.desdelinux.net/aprende-a-prescindir-del-entorno-grafico/
              https://blog.desdelinux.net/9-comandos-combinaciones-muy-divertidos-e-inutiles-de-linux/
              https://blog.desdelinux.net/con-el-terminal-apropos-un-comando-para-saber-que-hace-otro-comando/
              https://blog.desdelinux.net/mas-de-400-comandos-para-gnulinux-que-deberias-conocer/
              https://blog.desdelinux.net/alias-atajos-para-la-terminal/
              https://blog.desdelinux.net/comandos-mas-usados-por-ti/
              https://blog.desdelinux.net/apagar-y-reiniciar-mediante-comandos/

              You don't have to understand all the commands, but trust me, they will be a lot of fun for you 😀
              Don't be afraid of the terminal, it doesn't hurt 😉

              Greetings and you know, if you need anything else ... here on this site we like to help 🙂


            10.    veronicab said

              Thanks KZ 😀

              Until any moment.


  13.   Sergio said

    now we are at 17.