« June 2009 | Main | August 2009 »

Wednesday, July 15, 2009

Critical Firefox 3.5 Security Flaw

The newest Firefox, version 3.5, includes Tracemonkey, a new feature designed to speed up Javascript scripts. A flaw within Tracemonkey could allow attackers to remotely install evil software when users visit compromised Web sites.

A simple fix is available until the next patch fixes the vulnerability:

  1. Open up a new Firefox window and type ‘’about:config‘’ (without the quotes) in your browser's address bar
  2. In the ‘’filter‘’ box, type ‘’jit‘’ and a setting called ‘’javascript.options.jit.content‘’ will appear.
  3. If the setting is set to ‘‘true’’ it means the option is enabled.
  4. If it is, double-click on the setting. This should change the option to ‘’false‘’ disabling it.

Another Insecure ActiveX? You Betcha!

ActiveX flaws pop up on a regular basis so forget the explanation. Go to Microsoft and click the ‘’Fix It‘’ icon under ‘’Enable Workaround‘’ and following the instructions.

Posted by Matthew Carrick at 11:43.46 AM EDT | Permanent Link

| Categories: Security Alerts, Viruses-Trojans-Worms
Archives

Archive Index
Categories
Adobe
Adware/Spyware
All Things Mac
Alternative Apps
Best Practices
Bluetooth
Concepts
Eudora Email
Firefox Extensions
Google Chrome
Hardware Innovations
Hardware Recalls
Headlines
Instant Messaging
Internet Explorer
Mac Safari Browser
Mobile
Mozilla Firefox
Mozilla Thunderbird
Online Apps
Openoffice.org
Open Source
Opera
Penelope Email
Physical Security
Privacy Issues
RSS Applications
Security Alerts
Software Tools
Technology
TPDBP
Viruses-Trojans-Worms