PDA

View Full Version : A "highly critical" Firefox 3.5 vulnerability.



JillSwift
July 15th, 2009, 04:28 PM
Mozilla Firefox Memory Corruption Vulnerability (http://secunia.com/advisories/35798/)

I'm not sure how serious to take the "highly critical" part. They offer a simple work-around, though:
Set "javascript.options.jit.content" to "false" by opening about:config.

ukripper
July 15th, 2009, 04:41 PM
Or use noscript plugin to disable javascript running in the background for the untrusted sites.;)

Eviltechie
July 15th, 2009, 05:20 PM
Some guy said he had to do that on twitter this morning, only that that option didn't exist.

ghindo
July 15th, 2009, 05:27 PM
Mozilla's usually pretty good about patching these things ASAP. We'll see how long it takes them.

aysiu
July 15th, 2009, 06:11 PM
I think "highly critical" refers to the severity of the flaw, not to the likelihood of it being exploited, especially since it relies on social engineering (you have to be tricked into viewing a malicious page).

Pogeymanz
July 15th, 2009, 08:06 PM
Some guy said he had to do that on twitter this morning, only that that option didn't exist.

You can create your own entries in about:config. I recommend you tweet this guy and let him know. (I don't know how twitter works at all...)