Original URL: http://www.theregister.co.uk/2009/07/17/firefox_update/
Firefox update fixes zero-day JavaScript flaw
Just-in-Time vuln fixed in nick of time
Posted in Applications, 17th July 2009 10:18 GMT
Free whitepaper – Hands on with Hyper-V 3.0 and virtual machine movement
Mozilla has released an update version of Firefox that addresses a previously unpatched flaw that has become the target of hacking attacks over recent days.
Firefox 3.5.1 [1], released on Thursday, resolves a Just-in-Time (JIT) JavaScript compiler flaw in version 3.5 of the popular open source browser software, as explained in Mozilla's advisory here [2]. Exploits based on the vulnerability were posted on a security site on Tuesday so Mozilla deserves credit for acting promptly on what might otherwise have been a potentially nasty problem that posed [3] memory corruption and malware injection risks.
The latest update also corrects a performance issue [4] that resulted in slow start-up on Windows systems.
Users are advised to apply the update, remembering to re-enable the Just-in-Time compiler in cases where Mozilla's previously suggested workaround has been applied. ®
Links
- http://www.mozilla.com/en-US/firefox/3.5.1/releasenotes/
- http://www.mozilla.org/security/announce/2009/mfsa2009-41.html
- http://secunia.com/advisories/35798/3
- https://support.mozilla.com/tiki-view_forum_thread.php?forumId=1&comments_threshold=0&comments_parentId=381674&comments_offset=0&comments_per_page=20&thread_style=commentStyle_plain
