15 Jul 2009
Mozilla is warning users and administrators of a critical JavaScript flaw in its Firefox 3.5 browser.
The company said that the problem exists in the browser's JavaScript tool within a component called 'just in time' (JIT). If exploited, the vulnerability could allow an attacker to remotely execute code on a targeted system.
Mozilla further warned that a working exploit has been publically released, increasing the risk of attacks occurring in the wild.
A Firefox security alert offers instructions on how to temporarily disable the JIT component through the browser's about:config menu. Doing so will slow JavaScript performance, however.
Users can also reduce the risk of attack by running the browser in Windows Safe Mode.
The flaw is the latest in a string of high-profile browser exploits in recent days. Last week Microsoft warned of a flaw in a video ActiveX plug-in that was actively being targeted in Internet Explorer, and yesterday the company reported a second vulnerable IE component, this time an Office plug-in, that was being targeted by attackers.
Latest stories from Open Source
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
EU data protection overhaul contains "bureaucratic tick box-proposals", says information commissioner Christopher Graham in exclusive interview with V3
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
INSIDE SALES / BUSINESS DEVELOPMENT WEST LONDON...
QA Tester | Peterborough, Cambridgeshire...
TECHNICAL SALES / ACCOUNT EXECUTIVE / WEST LONDON / MARKET...
TECHNICAL SALES / BUSINESS DEVELOPMENT WEST LONDON...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
NoScript
Does using NoScript Add-on and only allowing sites you know avoid the issue?
Posted by: Jim 16 Jul 2009