Danger! Firefox 3.5 Has A Highly Critical Security Flaw

firefox-logo1 As reported by the Milw0rm website, Firefox 3.5 has one big security vulnerability (entitled Firefox 3.5 Heap Spray Vulnerabilty) which exists in Tracemonkey, the new JavaScript rendering engine developed by Mozilla. The instructions for hackers regarding how to use the Firefox 3.5 security flaw can be found already online, therefore an attacker is able to take total control of any computer running Firefox 3.5 through remote code execution techniques, because a patch is not yet available. Mozilla has confirmed the existence of the Firefox browser vulnerability in the way in which JavaScript is handled by Tracemonkey engine.

On the other hand, Secunia has rated this Firefox 3.5 security as being “highly critical”, allowing to the attacker to access the system remotely: “The vulnerability is caused due to an error when processing JavaScript code handling e.g. “font” HTML tags and can be exploited to cause a memory corruption. Successful exploitation allows execution of arbitrary code.” This type of vulnerability could also be found in previous versions of Firefox too, according to Secunia.

The critical security flaw, discovered in version 3.5 of Firefox web browser is easy to fix by following the next two steps, such that Tracemonkey Javascript engine will be disabled: enter about:config in the browser address bar and from the advanced preferences window set the value false for javascript.options.jit.content by double clicking on its corresponding entry.

The disabling of the Tracemonkey Javascript engine in Firefox 3.5 will definitely lead to a decrease of the web pages loading performance, but will keep your computer safe, until a patch will be released.

http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/digg_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/reddit_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/dzone_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/stumbleupon_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/delicious_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/blinklist_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/furl_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/newsvine_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/technorati_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/magnolia_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/google_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/facebook_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/yahoobuzz_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/sphinn_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/mixx_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/twitter_48.png
Tags: , , , ,

Related Articles

3 Responses to “Danger! Firefox 3.5 Has A Highly Critical Security Flaw”

  1. Ronicey Says:

    I typed in about:config & I did not see “javascript.options.jit.content”

    http://i118.photobucket.com/albums/o81/roniceb/aboutconfig.jpg

    The only thing close was “javascript.options.showInConsole” so I changed that from true to false.

    Are you sure we are supposed to type in “javascript.options.jit.content”?

  2. admin Says:

    You might have missed the previous entries in the list: javascript.options.jit.content options are located in the about:config web page just right before javascript.options.showInConsole.

  3. Get Firefox 3.5.1: Without Critical Security Flaws | Internet News | Free Download Windows Software Says:

    [...] previous article, there were explained the details of the highly critical security vulnerability of Firefox 3.5: “ The vulnerability is caused due to an error when processing JavaScript code handling e.g. [...]

Leave a Reply