Highly Critical JavaScript vulnerability in Firefox 3.5

MUff1N

Computer Enthusiast
Pro User
Local time
1:53 PM
Messages
268
Location
Payson/AZ
Critical JavaScript vulnerability in Firefox 3.5

07.14.09 - 10:15am
Issue
A bug discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler was disclosed publicly yesterday. It is a critical vulnerability that can be used to execute malicious code.
Impact
The vulnerability can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code. The vulnerability can be mitigated by disabling the JIT in the JavaScript engine. To do so:

  1. Enter about:config in the browser’s location bar.
  2. Type jit in the Filter box at the top of the config editor.
  3. Double-click the line containing javascript.options.jit.content setting the value to false.
Note that disabling the JIT will result in decreased JavaScript performance and is only recommended as a temporary security measure. Once users have been received the security update containing the fix for this issue, they should restore the JIT setting to true by:

  1. Enter about:config in the browser’s location bar.
  2. Type jit in the Filter box at the top of the config editor.
  3. Double-click the line containing javascript.options.jit.content setting the value to true.
Alternatively, users can disable the JIT by running Firefox in Safe Mode. Windows users can do so by selecting Mozilla Firefox (Safe Mode) from the Mozilla Firefox folder.
 

Attachments

  • About-Config.jpg
    About-Config.jpg
    13.4 KB · Views: 17

My Computer

Computer Manufacturer/Model Number
ABS Tech Ultimate X9
OS
Windows® 7 Ultimate x64 SP1
CPU
Intel Core 2 Duo E8400 (E0) @ 4.0GHz
Motherboard
ASUS P5Q Pro Turbo / 1780 FSB
Memory
G.SKILL-F2-8500CL5D-4GBPK (2x2Gbs) (5-5-5-15) @ 1067Mhz
Graphics Card(s)
EVGA GTX 470 SC (845/1690/2000) 160Gbs
Sound Card
VIA HD Audio / Boston Acoustics
Monitor(s) Displays
Acer X222W HD 22" LCD 2500:1 / 5ms
Screen Resolution
1680x1050
Hard Drives
Seagate Barracuda SATAII 2 x 320GB
Seagate Barracuda SATAII 1Tb
Intel® Rapid Storage Technology v10.1.0.1008
AHCI-NCQ Enabled
PSU
Silent Pro GOLD 80 PLUS 800w /95% efficiency / SLI-Crossfire
Case
ABS Stealth Black-Custom
Cooling
CoolerMaster V6GT 6 Heatpipe 200w CPU Cooler
Keyboard
Logitech G15 Gaming Keyboard (Old Style Blue!)
Mouse
Logitech MX518 Gaming Mouse
Internet Speed
1Mbs-up/ 6Mbs-down
If you don't mind a few bugs install the Nightly build

For those that don't mind a few bugs here & there you can also use the newest Nightly build Minefield v3.6a1pre which has this issue FIXED!

So you see they are already on top of this & will add this fix to 3.5 shortly for Public release!~
You can download that here... Index of /pub/mozilla.org ... est-trunk/

I just switched to the Nightly build "Minefield" 3.6 & it's really fast! No bugs I can report...
If you use this addon Nightly Tester Tools you can still use all your favorite extensions & themes too!
Just click the Override All Compatibility button (screeny) & it's fixed! So far everything works fine...man it's fast!
eek.gif


You can download the Nightly Tester Tools addon here---> https://addons.mozilla.org/en-US/firefox/addon/6543
 

Attachments

  • Nightly Tester Tools Override all Compatibility.jpg
    Nightly Tester Tools Override all Compatibility.jpg
    42.1 KB · Views: 15

My Computer

Computer Manufacturer/Model Number
ABS Tech Ultimate X9
OS
Windows® 7 Ultimate x64 SP1
CPU
Intel Core 2 Duo E8400 (E0) @ 4.0GHz
Motherboard
ASUS P5Q Pro Turbo / 1780 FSB
Memory
G.SKILL-F2-8500CL5D-4GBPK (2x2Gbs) (5-5-5-15) @ 1067Mhz
Graphics Card(s)
EVGA GTX 470 SC (845/1690/2000) 160Gbs
Sound Card
VIA HD Audio / Boston Acoustics
Monitor(s) Displays
Acer X222W HD 22" LCD 2500:1 / 5ms
Screen Resolution
1680x1050
Hard Drives
Seagate Barracuda SATAII 2 x 320GB
Seagate Barracuda SATAII 1Tb
Intel® Rapid Storage Technology v10.1.0.1008
AHCI-NCQ Enabled
PSU
Silent Pro GOLD 80 PLUS 800w /95% efficiency / SLI-Crossfire
Case
ABS Stealth Black-Custom
Cooling
CoolerMaster V6GT 6 Heatpipe 200w CPU Cooler
Keyboard
Logitech G15 Gaming Keyboard (Old Style Blue!)
Mouse
Logitech MX518 Gaming Mouse
Internet Speed
1Mbs-up/ 6Mbs-down
Nice catch MUff1N

Thanks for the link also.:)
 

My Computer

Computer Manufacturer/Model Number
Cheap $399.00 E-Machine
OS
Windows 7 Pro & Vista Home Premium
CPU
Athlon 64 3800+ (Orleans) 2.40GHz
Motherboard
Winfast
Memory
2GB DDR2 RAM DIMM
Graphics Card(s)
NVIDIA GeForce 8500 GT 512 MB memory HDMI out
Sound Card
creative X-Fi Exteme 7..1 channel
Monitor(s) Displays
Acer V223W 22" widescreen DVI
Screen Resolution
1680x1050
Hard Drives
WDC WD5 500GB
WDC WD25 250GB
PSU
OCZ 550 watt
Case
Gateway
Cooling
2 fans
Keyboard
Dell
Mouse
Sony Vaio
Internet Speed
18MB/s down - .72MB /s up
As I said, fixed by the end of the week!

As I said they more than likely by the end of the week would have Firefox patched & they have!
thumbsup.gif

So if you're still using 3.5 go get the updated patched version now! Mozilla | Firefox web browser & Thunderbird email client

If you applied the jit work-around fix you'll have to manually undo it as that setting won't change just because you updated Firefox.
wink.gif
 

My Computer

Computer Manufacturer/Model Number
ABS Tech Ultimate X9
OS
Windows® 7 Ultimate x64 SP1
CPU
Intel Core 2 Duo E8400 (E0) @ 4.0GHz
Motherboard
ASUS P5Q Pro Turbo / 1780 FSB
Memory
G.SKILL-F2-8500CL5D-4GBPK (2x2Gbs) (5-5-5-15) @ 1067Mhz
Graphics Card(s)
EVGA GTX 470 SC (845/1690/2000) 160Gbs
Sound Card
VIA HD Audio / Boston Acoustics
Monitor(s) Displays
Acer X222W HD 22" LCD 2500:1 / 5ms
Screen Resolution
1680x1050
Hard Drives
Seagate Barracuda SATAII 2 x 320GB
Seagate Barracuda SATAII 1Tb
Intel® Rapid Storage Technology v10.1.0.1008
AHCI-NCQ Enabled
PSU
Silent Pro GOLD 80 PLUS 800w /95% efficiency / SLI-Crossfire
Case
ABS Stealth Black-Custom
Cooling
CoolerMaster V6GT 6 Heatpipe 200w CPU Cooler
Keyboard
Logitech G15 Gaming Keyboard (Old Style Blue!)
Mouse
Logitech MX518 Gaming Mouse
Internet Speed
1Mbs-up/ 6Mbs-down
Back
Top