Mozilla is warning users and administrators of a critical JavaScript flaw in its Firefox 3.5 browser. Bug was discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler was disclosed publicly yesterday. It is a critical vulnerability that can be used to execute malicious code.
The vulnerability can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code. The vulnerability can be mitigated by disabling the JIT in the JavaScript engine.
about:configjitjavascript.options.jit.contentNote that disabling the JIT will result in decreased JavaScript performance and is only recommended as a temporary security measure. Once users have been received the security update containing the fix for this issue, they should restore the JIT setting to true by:
about:configjitjavascript.options.jit.contentAlternatively, users can disable the JIT by running Firefox in Safe Mode. Windows users can do so by selecting
Mozilla Firefox (Safe Mode)
from the Mozilla Firefox folder.
Mozilla developers are working on a fix for this issue and a Firefox security update will be sent out as soon as the fix is completed and tested. The flaw is the latest in a string of high-profile browser exploits in recent days.
2 Responses to Mozilla warns about JavaScript vulnerability in Firefox 3.5
Firefox 3.5.1 update now available | Geekword
July 17th, 2009 at 10:49 am
[...] of days back we informed you guys about the existence of Javascript vulnerability in Firefox 3.5. Well the Firefox team has been very speedy and quick and has released version 3.5.1 of the browser [...]
Yet another vulnerability issue arises for Firefox 3.5.1 | Geekword
July 19th, 2009 at 10:40 pm
[...] just a few days since we informed you about the Firefox 3.5.1 update that was aimed at resolving a Javascript vulnerability found in Firefox 3.5. Well unfortunately another vulnerability has been found in Firefox 3.5.1. The latest vulnerability [...]