Forum Thread: Firefox 3.6.2 (64-bit) detected as 3.6(.0)

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
Mozilla Foundation
And, this specific program:
Mozilla Firefox 3.6.x

This thread has been marked as locked.
Whizzmo Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 24th Mar, 2010 23:06
Ranking: 0
Posts: 7
User Since: 24th Mar, 2010
System Score: N/A
Location: US
Last edited on 24th Mar, 2010 23:11

Download page: http://wiki.mozilla-x86-64.com/Firefox:Download
Download direct link: http://wiki.mozilla-x86-64.com/images/Firefox-3.6....

This is a 64-bit version of Firefox 3.6.2 (Namoroka). PSI 1.5.0.1 detects this as "Firefox 3.6.x (64-bit)" version 3.6 , and ascribes to it all the vulnerabilities that were since patched in 3.6.2 .

A re-scan did not seem to change PSI's detection of this "vulnerability". Perhaps this file needs to be scanned/diagnosed via hash instead of file version? :(


Path:
XX:\Program Files (x86)\Namoroka (64-bit)\firefox.exe

USER_AGENT string:
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.2) Gecko/20100324 Namoroka/3.6.2 (.NET CLR 3.5.30729)

This user no longer exists RE: Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 25th Mar, 2010 08:37
Hi,

Could I ask you to ensure you have all the latest FF updates by clicking Help > Check for updates? If any updates are available, please install them and rescan with the PSI.

If this doesn't work, can I ask you to post the version number of the firefox.exe file? You can get this by navigating to the entry the PSI flags as insecure, opening the containing directory and right-clicking, selecting "properties". The version number of the firefox.exe file should be 1.9.2.3667. If so, you are up to date.

You aren't thinking of the "patched" or "secure browsing" tab, are you? Patched refers to vulnerabilities you've already fixed, and the Secure Browsing tab frequently show problems for which there is no solution, to help you estimate the relative security of different browsers.

hope this helps.
Was this reply relevant?
+0
-0
Whizzmo RE: Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 25th Mar, 2010 11:05
Score: 0
Posts: 7
User Since: 24th Mar 2010
System Score: N/A
Location: US
Last edited on 25th Mar, 2010 11:07
on 25th Mar, 2010 08:37, wrote:
Hi,

Could I ask you to ensure you have all the latest FF updates by clicking Help > Check for updates? If any updates are available, please install them and rescan with the PSI.

If this doesn't work, can I ask you to post the version number of the firefox.exe file? You can get this by navigating to the entry the PSI flags as insecure, opening the containing directory and right-clicking, selecting "properties". The version number of the firefox.exe file should be 1.9.2.3667. If so, you are up to date.

You aren't thinking of the "patched" or "secure browsing" tab, are you? Patched refers to vulnerabilities you've already fixed, and the Secure Browsing tab frequently show problems for which there is no solution, to help you estimate the relative security of different browsers.

hope this helps.


Help -> Check for Updates returns "There are no updates available..."

Oddly, my (64-bit) firefox.exe file version is 1.9.2.3666 . Do you happen to remember where you got the .3667 version from?

I should have been more explicit: PSI shows the 64-bit firefox v3.6.2 as insecure on the Secure Browsing tab and the Insecure tab, for me. My query regarded the detection of the 32-bit version of firefox as having a version of "3.62" while the 64-bit version is only detected as having a version of "3.6" .

Does this help clear things up?
Was this reply relevant?
+0
-0
This user no longer exists RE: Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 25th Mar, 2010 12:15
Hi,

This should now have been corrected. Please try a rescan, and inform me of the results.

hope this helps.
Was this reply relevant?
+0
-0
MajorEvent RE: Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 25th Mar, 2010 20:00
Score: 1
Posts: 5
User Since: 31st Oct 2009
System Score: N/A
Location: US
Exact same problem here with Win 7 x64. Updated Firefox using the Secunia PSI direct download link. EVEN AFTER DELETING FIREFOX COMPLETELY, PSI continued to insist the firefox.exe file existed and was insecure when rescanning (IT DID NOT). Something very screwed up here (with PSI it would seem). I have three Win7 x64 PC's all running Firefox and only the one has this problem.

TIA
MajorEvent
Was this reply relevant?
+0
-0
Whizzmo RE: Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 25th Mar, 2010 21:22
Score: 0
Posts: 7
User Since: 24th Mar 2010
System Score: N/A
Location: US
on 25th Mar, 2010 12:15, wrote:
Hi,

This should now have been corrected. Please try a rescan, and inform me of the results.

hope this helps.


Sadly, this program is still mis-detected by a fresh scan. If it helps, the SHA-256 hash of my firefox.exe is 3de4b172f20c69d1934ac4f486d7d38bc30ec8a3a68a4f110c 9761befe8a21c2 (as reported by HashTab).
Was this reply relevant?
+0
-0
Whizzmo Any update?
Member 27th Mar, 2010 02:37
Score: 0
Posts: 7
User Since: 24th Mar 2010
System Score: N/A
Location: US
As of 26 Mar. 2010, 18:34, a fresh scan still (mis-)detects this file version. Is there any other information that you need from my end to troubleshoot this?
Was this reply relevant?
+0
-0
This user no longer exists RE: Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 29th Mar, 2010 10:07
Hi,

We need another version number from your end, namely the "Product Version" number of firefox.exe

To get this, you can click "Open folder" from the Firefox entry in the PSI, then right-click, select "Properties", go to "Version" and paste the contents of the field "Product Version" here.

Thank you.
Was this reply relevant?
+0
-0
Whizzmo RE: Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 29th Mar, 2010 11:44
Score: 0
Posts: 7
User Since: 24th Mar 2010
System Score: N/A
Location: US
on 29th Mar, 2010 10:07, wrote:
Hi,

We need another version number from your end, namely the "Product Version" number of firefox.exe

To get this, you can click "Open folder" from the Firefox entry in the PSI, then right-click, select "Properties", go to "Version" and paste the contents of the field "Product Version" here.

Thank you.


Product Version: 3.6

Other data from that page, should they be helpful:
BuildID: 20100114101655
File Version: 1.9.2


Thanks!
Was this reply relevant?
+0
-0
This user no longer exists RE: Firefox 3.6.2 (64-bit) detected as 3.6(.0)
Member 29th Mar, 2010 12:47
Hi,

The version number in that field should be "3.6.2". After testing it, we've determined it works without problems on x64 systems. If you still have a problem, I suggest you try reinstalling Firefox. However, if your help > About Mozilla Firefox > shows 3.6.2, you should be up to date.

hope this helps.
Was this reply relevant?
+0
-0

This thread has been marked as locked.