Firefox 2.0.0.10
Firefox 2.0.0.10 was released last week. This of course means that everyone should be upgraded to the latest and greatest version by now. It's always extremely important to keep the web browser up to date given it processes an amazing amount of untrusted content.
On the note of Firefox, I ran across this rather interesting study regarding Mozilla security flaws:
http://www.st.cs.uni-sb.de/softevo/vulnerabilities.php
I'm tempted to attempt such an analysis over the Fedora codebase to see how things fare.
Insecurity Blues
Jeremy Allison has writeup regarding his thoughts on the recent Samba security issues.
http://www.tuxdeluxe.org/node/273
His words really do apply to most open source projects today. Security in the open source world does indeed tend to be a well orchestrated mess