Zero-day flaw found in Firefox 3.5

By Tom Espiner, ZDNet UK
Thursday, July 16, 2009 09:47 AM

There is a critical JavaScript vulnerability in the Firefox 3.5 Web browser, Mozilla has warned.

The zero-day flaw lies in Firefox 3.5's Just-in-time (JIT) JavaScript compiler. Proof-of-concept code to exploit the vulnerability has been posted online by a security research group, Mozilla said in a post on its security blog on Wednesday. Security company Secunia rated the vulnerability as "highly critical" on Wednesday.

The hole could allow a hacker to launch a "drive-by" attack, according to Mozilla. That means an attacker may be able to execute malicious code on a target machine if the victim visits a Web site containing an exploit.

No patch is currently available, but Mozilla developers are working on a fix. A workaround suggested in the blog post is to disable the Firefox 3.5 JIT compiler. However, Mozilla warned this would result in decreased JavaScript performance in Firefox.

The JIT compiler is part of TraceMonkey, which was added to Firefox for its 3.5 update released at the end of June. TraceMonkey is meant to optimize the browser which is faster than previous iterations of Firefox, according to Mozilla.

On Wednesday, the U.S. Computer Emergency Response Team said users and administrators should completely disable JavaScript functionality in Firefox 3.5.

The Sans Institute also said people could disable JavaScript and suggested using NoScript, an open-source Firefox plug-in that only allows script to be executed by trusted Web sites.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

Zero-day flaw found in Firefox 3.5
I hear Firefox 3.5.1 was released earlier today to fix this vulnerability, at least temporarily.

Note to AppGuard and EdgeGuard users, you do not need this patch and you might as well wait a week and perform updates to all of your software applications at once.
Posted by Eirik Iverson on Friday, July 17 2009 03:02 AM


Tech Jobs Now!

Search for your ideal tech job:

10 open source projects worth checking out

Open Source

The open source field is pretty crowded, but certain projects stand above the rest. Here are 10 tools and solutions you don't want to overlook.


Read more



Will technology divide us further?

Blog thumbnail

So I finally watched 2012 over the weekend, but the film left me feeling extremely agitated.

The possibility that the world may meet its watery end in three years didn't..... by Eileen Yu

Read more

Tags

  1. advertisement
  2. blog
  3. facebook
  4. google inc.
  5. internet
  6. internet advertising
  7. microsoft corp.
  8. network
  9. revenue
  10. search
  11. social networking
  12. software
  13. u.s.
  14. web
  15. web 2.0
  16. web browser
  17. web browsers
  18. web services
  19. web sites
  20. yahoo! inc.