2005-05-07 Trunk builds

Exciting fixes:

Security fixes:

  • Partially fixed: 289074 - Security hole in markLinkVisited (Bug 217195) has not been fixed.
  • Fixed: 289675 - Getter/setter on window.__proto__.__proto__.__proto__ allows XSS attacks.
  • Fixed: 290079 - Arbitrary code execution via sidebar (part 2).
  • Fixed: 290038 - Search plugins can silently overwrite existing search plugins.
  • Fixed: 290037 - Search plugins can get javascript access to currently active tab.
  • Fixed: 290036 - Link tag allows to execute arbitrary code without user interaction.
  • Fixed: 289204 - Showing a blocked popup has chrome privs.

If you're using an old trunk build, you should upgrade to a new trunk build or switch to 1.0.3 so you're not vulnerable to these holes.

More fixes:

  • Fixed: 210043 - Enable context menu "copy image" on more platforms.
  • Fixed: 258277 - Add menu item to Check for Updates.
  • Fixed: 228968 - Downloading a large file >2GB displays negative status values.
  • Fixed: 292326 - Arrowscrollbox doesn't scroll on hover.
  • Fixed: 283897 - VBulletin 3.0.1 WYSIWYG Post Reply Function is Broken.
  • Fixed: 240276 - Reorganize nsGfxScrollFrame.
  • Fixed: 180962 - Insecure form submission warning pops up twice (in the first tab).
  • Fixed: 245631 - Crash loading .ico file [@ nsICODecoder::ProcessData ].
  • Fixed: 96423 - German character ß - buggy capitalization (text-transform: uppercase or capitalize).
  • Fixed: 268513 - Overflow:scroll causes memory growth.
  • Fixed: 220626 - Enable keyboard access to Blocked Popups notification bar.
  • Fixed: 189982 - Automatic image resizing: state of the image should be kept after resizing the browser window.
  • Fixed: 53995 - [Windows] Using "text zoom" to scale fonts very small makes them come back normal.
  • Fixed: 231300 - [Windows] NsLocalFile::MoveTo is very slow to move directories.
  • Fixed: 239218 - [Mac] Menus are nonfunctional when 'tools' have focus (Downloads / Extensions / Theme Managers, JavaScript Console and Page Info window).

New features for web developers and extension developers:

  • Fixed: 290592 - Array extras: forEach, indexOf, filter, map, some, every.
  • Fixed: 274928 - Make it possible for apps, extensions, and vendors to all add tokens to the User-Agent string (using default preferences) without overwriting each other (general.useragent.extra.*).
  • Fixed: Many changes to Extension Manager

Fixes for regressions:

  • Fixed regression: 289211 - "Open a new window" (e.g. Ctrl+N) doesn't load the home page (since Apr 5).
  • Fixed regression: 288509 - Dragging favicon from location bar into bookmark menu creates double entry (since Mar 30).
  • Fixed regression: 273466 - Can't drag favicon from url bar into bookmark sidebar to create bookmark (since Aviary landing).

Many extensions won't work right away when you upgrade to this version, but if you reinstall the extensions, most will work.

Most serious fastback bugs:

  • With fastback: 292933 - Info. popup box on tinderbox display wrong details.
  • With fastback: 292934 - Favicon not updated when going back/forward in tab.
  • With fastback: 293235 - When using the back button (or keyboard), visited links are not marked as visited.

Regressions (new bugs):

  • Since May 5: 293135 - Form content is lost when pressing back (regardless of whether fastback is enabled).
  • Since Apr 29 : 292431 - 15% performance regression on DHTML due to fix for bug 240276.
  • Since Feb 24: 284245 - Richedit/designMode not working anymore at blogger.com.
  • Since Feb 23: 285544 - Safe Mode doesn't work.
  • Since ~Jan 22: 279497 - Selected profile does not always appear focused.
  • Since ??: 273200 - Ctrl+W in Find bar breaks middle-clicking links, find toolbar, and back button.
  • Since November on trunk: 269927 - Tooltip appears after closing tab.

Windows builds: Official Windows, Official Windows installer, Official Windows MSI (discussion)

Linux builds: Official Linux, Official Linux installer

Mac builds: Official Mac

16 Responses to “2005-05-07 Trunk builds”

  1. John Says:

    The link for “Official Windows” is wrong.

  2. Jesse Ruderman Says:

    John – Fixed. Thanks for catching that quickly.

  3. michaell Says:

    The exciting canvas fix would be more exciting if it had actually made it into the Firefox installer builds – bug 293280

  4. Andrew Says:

    I donated $20 before I went to bed, and when I woke up there was already a new post. The “I want you to update The Burning Edge more often” checkbox on the donation form must really work!

  5. testboy Says:

    thanks for update on firefox development. keep up the great work!

  6. Nicholas Says:

    Woot! It’s back!

  7. pika unforgiven Says:

    great to see the burning edge back in action. with all these fixed vulnerabilities, i wonder how long it will be till the latest one at http://secunia.com/advisories/15292/ is going to be fixed.

  8. Kevin Says:

    Anyone else have the problemt that the bookmark toolbar folder doesn’t display its bookmarks? Mac Version
    -Kevin

  9. hemebond Says:

    It doesn’t load my bookmarks at all. I have bookmarks.file specified but it just doesn’t bother with it, nor does it load the default. There’s one message in the Javascript console about an extension being loaded and failing.

  10. hemebond Says:

    Okay, I’ve created a new profile and everything seems to be working great.

  11. Joey Says:

    yay! you’re baaaaaaacckkk!!!

  12. hemebond Says:

    It was the Developer Toolbar extension causing problems. No update available yet.

  13. MacD Says:

    Same probs here as Hemebond has. Unfortunately, WebDeveloper extension is one of main reasons I use Firefox, and I’m nothing without my bookmarks ;) So still using some 20th of April build.. (OS X 10.4.1 here..)

  14. ANBO Motohiko Says:

    > Unfortunately, WebDeveloper extension is one of main reasons I use Firefox, and I’m nothing without my bookmarks ;) So still using some 20th of April build..

    I have a patch for webdeveloper 0.9.3. Please see
    my journal entry (Japanese page).

  15. Manoj Mehta Says:

    Bug 292431 has been fixed. It’s great to have you back.

  16. MacD Says:

    >I have a patch for webdeveloper 0.9.3. Please see
    my journal entry (Japanese page).

    Thanks alot. It works now! :)