Slashdot Mirror


Firefox 3.5's First Vulnerability "Self-Inflicted"

CWmike writes "Mozilla has confirmed the first security vulnerability in Firefox 3.5, saying that the bug could be used to hijack a machine running the company's newest browser. A noted Firefox contributor called the situation 'self-inflicted' and said it was likely that the hacker who posted public exploit code Monday became aware of the flaw by rooting through Bugzilla, Mozilla's bug- and change-tracking database. The vulnerability is in the TraceMonkey JavaScript engine that debuted with Firefox 3.5, said Mozilla. '[It] can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code,' Mozilla's security blog reported Tuesday."

5 of 156 comments (clear)

  1. Yeah, right by DoofusOfDeath · · Score: 5, Funny

    '[It] can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code,' Mozilla's security blog reported Tuesday."

    Oh sure, I'm definitely going to follow that link now.

  2. Re:Nice test for the open source community by fedxone-v86 · · Score: 5, Informative

    If you had read the bugzilla thread (I know, I know) you'd know it's already fixed ;)

    --
    (USER WAS PUT ON PROBATION FOR THIS POST)
  3. Re:WTF by maxume · · Score: 5, Insightful

    So when they know about and are actively working on fixing a bug that is an exploit vulnerability, you think they should do it in public?

    I get the argument that telling your users about it means that they can protect themselves (say, by running noscript), but for a consumer facing organization like Mozilla, the majority of users aren't going to notice or do anything.

    --
    Nerd rage is the funniest rage.
  4. Temporary fix by AdmiralXyz · · Score: 5, Informative

    According to TFA, the temporary fix is to disable TraceMonkey (JavaScript will still work). Set 'javascript.options.jit.content' in about:config to false until the patch is released.

    --
    Dislike the Electoral College? Lobby your state to join the National Popular Vote Interstate Compact.
  5. Re:MOD PARENT UP by the+way,+what're+you · · Score: 5, Funny

    I've got at least a dozen non-default settings I've set in about:config. What's one more?

    at least a baker's dozen?

    --
    example.org - powered by Linux!