The next version of Ubuntu is coming soon
  • Kindle Fire, Full Color 7
    Kindle Fire, Full Color 7" Multi-touch Display, Wi-Fi
    Amazon Digital Services, Inc
  • Apple TV MC572LL/A (NEWEST VERSION)
    Apple TV MC572LL/A (NEWEST VERSION)
    Apple Computer
  • Amazon.com Gift Cards - Print at Home
    Amazon.com Gift Cards - Print at Home
    Amazon

Lifehacker RSS feed

« Firefox 3.5 critical JIT fix available for download | Main | Another Patch Tuesday passes without plugging all the holes. »
Wednesday
Jul152009

Firefox 3.5 JavaScript exploit workaround

400px-circle-style-warningsvg1-150x1501Firefox 3.5 has a vulnerability in the JavaScript compiler that can be exploited by an attacker to allow execution of arbitrary code. The vulnerability can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code.

To disable the vulnerable component, open up a new Firefox window and type "about:config" (without the quotes) in the browser's address bar. In the "filter" box, type "jit" and you should see a setting called "javascript.options.jit.content". You should notice that beside that setting it reads "true," meaning the setting is enabled. If you just double-click on that setting, it should disable it, changing the option to "false."

Alternatively, users can disable the JIT by running Firefox in Safe Mode.  Windows users can do so by selecting Mozilla Firefox (Safe Mode) from the Mozilla Firefox folder.

http://www.kb.cert.org/vuls/id/443060 US-CERT  Mozilla Firefox 3.5 TraceMonkey JavaScript engine uninitialized memory vulnerability

http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/ Critical JavaScript vulnerability in Firefox 3.5

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
All HTML will be escaped. Hyperlinks will be created for URLs automatically.