Firefox
The vulnerability affects current versions of Firefox for all major PC platforms

Critical JavaScript flaw hits Firefox

Error could allow for remote exploits

Shaun Nichols in California

Mozilla has confirmed a potentially serious flaw in its open source Firefox browser. 

Developer Michal Zalewski, who uncovered the flaw, described it as " seemingly pretty nasty, and apparently easily exploitable".

Advertisement

The vulnerability affects current versions of Firefox for all major PC platforms, according to Zalewski's report.

The use of a certain JavaScript instruction can cause Firefox to crash, allowing an attacker complete access to a system and the ability to run malware remotely.

Zalewski said that the attack could be carried out by convincing a user to access a specially-crafted HTML file that hosts JavaScript code targeting the vulnerability.

Bugzilla, the error-tracking system used by Mozilla, classifies the vulnerability as 'critical', the second-highest priority.

The vulnerability has only been demonstrated as a proof-of-concept code and there have been no reports of active exploits.

The disclosure comes on the same day that Mozilla released an update for Firefox, which does not address the JavaScript flaw.

Mozilla and the US Computer Emergency Readiness Team urged users to mitigate the vulnerability by disabling JavaScript in Firefox.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

HTC Hero

Hands on with the HTC Hero

V3.co.uk gets a walk through of the Hero, which includes HTC's new Sense overlay for Android

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Carlos Solari

Interview: Bell Labs security chief Carlos Solari

The former FBI and White House CIO shares his views...

Virtual world

Intel outlines the next-generation 'reality web'

Forget Web 2.0, the future is 'immersive connective experience'

PowerPoint 2010

Microsoft spills the beans on Office 2010

Web-based versions of Office apps to be available at no...

HTC Hero

Hands on with the HTC Hero

V3.co.uk gets a walk through of the Hero, which includes...

Primary Navigation