Firebird and Mozilla Clarification
I've seen some mis-information on this in a couple of places now, so I feel the need to comment. A few days ago a vulnerability was reported in Mozilla/Firebird that allowed arbitrary code execution under windows. What some people seem to be missing is that this was a vulnerability in windows not Mozilla. The bug does not effect any OS but windows, and will probably be patched in XP SP2. Why some people are using this to say things like "see, it's not just IE that has problems" is beyond me. While Mozilla surely has bugs, let's view the facts on this one.
- Only Windows is vulnerable
- A Windows SP will address the issue
- A fix was provided by Mozilla within 12 hours of a report on FD
It is simply FUD to see this incident being used as an example of how OSS is flawed. If anything it's an example of how an OSS program was able to work around an OS issue in less than 12 hours, which is quite impressive to me. It's clear that some people still don't get it. We'll keep making our point with code and response times like this, instead of just talking about it.
--jeremy