Feeds

Mozilla blocks Firefox Java plugin

Plug out, baby

Choosing a cloud hosting partner with confidence

Mozilla has begun blocking an unsecured Java plugin for its Firefox browser.

The move, applied through the open source outfit's Plugin Check feature, is intended to protect Firefox fans from a recently discovered security flaw affecting the Java Deployment Toolkit on multiple flavours of Firefox.

Discussions on Bugzilla show this is unrelated to a flaw in Java Web Start affecting multiple browsers and patched by Oracle via an out-of-sequence (emergency) update last week.

Several other insecure plug-ins are already blocked through Plugin Check, as listed on Mozilla's website here. Often such moves are applied in response to frequent instances of browser crashes, a problem that applies to versions of Yahoo Application State Plugin, Skype and AVG SafeSearch, for example. In other cases, such as Apple QuickTime Plugin version 7.1, the block relates to a security vulnerability in the add-on software.

Screenshots illustrating how the Plugin Check technology blocks the Java plugin can be found in a blog post by F-secure here. Mozilla, which launched Plugin Check as a Firefox-only service last October, has plans to expand the technology to warn of potential problems with add-ons to other browsers, as explained in our earlier story here. ®

Internet Security Threat Report 2014

More from The Register

next story
Preview redux: Microsoft ships new Windows 10 build with 7,000 changes
Latest bleeding-edge bits borrow Action Center from Windows Phone
Google opens Inbox – email for people too thick to handle email
Print this article out and give it to someone tech-y if you get stuck
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Entity Framework goes 'code first' as Microsoft pulls visual design tool
Visual Studio database diagramming's out the window
Google+ goes TITSUP. But WHO knew? How long? Anyone ... Hello ...
Wobbly Gmail, Contacts, Calendar on the other hand ...
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
Ubuntu 14.10 tries pulling a Steve Ballmer on cloudy offerings
Oi, Windows, centOS and openSUSE – behave, we're all friends here
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.