Critical JavaScript vulnerability in Firefox 3.5 [with Temp Fix]

Status
Not open for further replies.

MaRKiV

Inactive
Contributor
Issue

A bug discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler was disclosed publicly yesterday. It is a critical vulnerability that can be used to execute malicious code.

Impact

The vulnerability can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code. The vulnerability can be mitigated by disabling the JIT in the JavaScript engine. To do so:

Enter
about:config
in the browser’s location bar.
Type
in the Filter box at the top of the config editor.
Double-click the line containing
javascript.options.jit.content
setting the value to false.

Note that disabling the JIT will result in decreased JavaScript performance and is only recommended as a temporary security measure.

Once users have been received the security update containing the fix for this issue, they should restore the JIT setting to true by:

Enter
about:config
in the browser’s location bar.
Type
in the Filter box at the top of the config editor.
Double-click the line containing
javascript.options.jit.content
setting the value to true.
Alternatively, users can disable the JIT by running Firefox in Safe Mode. Windows users can do so by selecting Mozilla Firefox (Safe Mode) from the Mozilla Firefox folder.

Status

Mozilla developers are working on a fix for this issue and a Firefox security update will be sent out as soon as the fix is completed and tested.

Source
 
This Bug has been fixed in the new Firefox version 3.5.1
Fixed in Firefox 3.5.1
MFSA 2009-41 Corrupt JIT state after deep return from native function

Source

It also addresses the issue that was making Firefox take a long time to load on some Windows systems.

Enjoy Folks :hap2::hap2:
 
Status
Not open for further replies.