Mozilla Firefox
Mozilla has identified a problem in Firefox's JavaScript tool

Mozilla warns of critical Firefox vulnerability

JavaScript flaw could allow for remote attacks

Shaun Nichols in San Francisco

Mozilla is warning users and administrators of a critical JavaScript flaw in its Firefox 3.5 browser.

The company said that the problem exists in the browser's JavaScript tool within a component called 'just in time' (JIT). If exploited, the vulnerability could allow an attacker to remotely execute code on a targeted system.

Mozilla further warned that a working exploit has been publically released, increasing the risk of attacks occurring in the wild.

A Firefox security alert offers instructions on how to temporarily disable the JIT component through the browser's about:config menu. Doing so will slow JavaScript performance, however.

Users can also reduce the risk of attack by running the browser in Windows Safe Mode.

The flaw is the latest in a string of high-profile browser exploits in recent days. Last week Microsoft warned of a flaw in a video ActiveX plug-in that was actively being targeted in Internet Explorer, and yesterday the company reported a second vulnerable IE component, this time an Office plug-in, that was being targeted by attackers.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Code

Comsec launches code checking service

Codefend could save money by catching security problems early on

MS bug

Microsoft responds to criticism over late fix

Flaw in ActiveX Control first reported in early 2008

Microsoft to plug security holes

Microsoft has given advance warning of a number of security fixes

Researchers crack Social Security number code

Obsolete system could increase the risk of identity theft

Related white papers

Related jobs

Most read stories

Most watched

Analysis and Reports

Storage-as-a-Service: Best efforts or best practice?
IDG research: IT professionals understand the fundamentals of managing and protecting data, but do not apply best practices

The seven security myths of Microsoft Windows 7
It is essential to separate myth from reality about the built-in security of Microsoft’s latest offering

Poll

VMworld 2010 poll

VMworld 2010 poll

How advanced is your firm's cloud computing strategy?

View poll results

White paper library

Attachmate

Smartstream

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

mark hurd

Mark Hurd appointed Oracle president

Charles Phillips out as former HP chief gets job with...

Cloud computing

CIMTrek offers path to the cloud for Lotus users

Tools help migrate Notes/Domino workflows to cloud-based alternatives

ViewSonic ViewPad 7

ViewSonic ViewPad 7 video

Hands on with 7in tablet that features phone capability and...

TalkTalk

ICO warns TalkTalk over URL tracking service

Watchdog criticises ISP for failing to inform customers of trial

Primary Navigation