
Sticking it to JavaScript
By Tom Espiner
Published: 16 July 2009 11:15 GMT
There is a critical JavaScript vulnerability in the Firefox 3.5 web browser, Mozilla has warned.
The zero-day flaw lies in Firefox 3.5's Just-in-time (JIT) JavaScript compiler. Proof-of-concept code to exploit the vulnerability has been posted online by a security research group, Mozilla said in a post on its security blog on Wednesday. Security company Secunia rated the vulnerability as highly critical on Wednesday.
The hole could allow a hacker to launch a 'drive-by' attack, according to Mozilla. That means an attacker may be able to execute malicious code on a target machine, if the victim visits a website containing an exploit.
No patch is currently available, but Mozilla developers are working on a fix. A workaround suggested in the blog post is to disable the Firefox 3.5 JIT compiler. However, Mozilla warned this would result in decreased JavaScript performance in Firefox.
The JIT compiler is part of TraceMonkey, which was added to Firefox for its 3.5 update released at the end of June. TraceMonkey is meant to optimise the browser, which is faster than previous iterations of Firefox, according to Mozilla.
On Wednesday, the US Computer Emergency Response Team said users and administrators should completely disable JavaScript functionality in Firefox 3.5.
The Sans Institute also said people could disable JavaScript, and suggested using NoScript, an open source Firefox plug-in that only allows script to be executed by trusted websites.
Original article: Huge demand for Windows 7 pre-orders in Europe from ZDNet UK
User Experience Developer - London - Finance, JavaScript, DHTML,CSS, Cross Browser Development, Ajax, JSP, Subversion or CVS A User Experience ...
An immediate opening has arisen for a penetration / Vulnerability tester who also has a broad general Info sec background. My client is a FTSE 100 ...
The aim now is to double the size of the business over the next three years.Purpose of the roleThe main basis of the role will be to design and ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business