The bug was classified as highly critical by Secunia, which warned that malicious people could exploit it via the execution of arbitrary code to take over other users' systems.
Secunia's report on the exploit can be read by clicking here.
"The vulnerability is caused due to an error when processing JavaScript code handling e.g. 'font' HTML tags and can be exploited to cause a memory corruption," Secunia warned.
Secunia said the original advisory was reported on the milwOrm website, and can be read by clicking here.
The vulnerability has so far been confirmed in Firefox 3.5, but Secunia said it may also affect other versions of the browser. Mozilla on Tuesday confirmed the vulnerability, and said that it can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code.
Mozilla said the vulnerability can be mitigated by disabling the JIT (Just-in-time) in the JavaScript engine, and offered code to do so. Users can also disable the JIT by running Firefox in the Safe Mode.
However, disabling the JIT is only a temporary measure, as such an action will cut JavaScript performance.
Mozilla said its developers are working on a fix for the vulnerability and will release a Firefox security update once the fix is ready.
- Juniper Honors 12 Americas Partners
- Facebook And Four More Web Sites We Love To Hate
- Cisco Honors Top Partners During 2010 Partner Summit
- HP Salutes Top Partners At APC 2010 Award Show
- Upclose And Personal With AMD And friends
- Will Oracle's Phillips' Affair Revelation Be A Distraction?
- Apple, Microsoft Unlikely Allies Against Google
- HP-Microsoft Cloud Partnership Needs To Show Us The Goods
- Blog: It's Time For A Cybercrime Public Service Announcement
- Nortel Sell-Off Continues: Ethernet Business To Ciena?
- Want To Deploy Exchange 2007 SP2 In A Server 2008 R2 Domain? Sorry
- Apple Improves iTunes 9 With Syncing, Visual Enhancements
- Oracle Ad Refutes Sun Hardware Fears
- U.S. Copyright Chief Rips Google Book Deal In Testimony
- Apple Slashes iPod Price Tags
- Price Is Right? Asus To Launch Low-Cost E-Reader
- Microsoft Xbox 360 Consoles Fail More Often Than Wii, PS3
- Privacy Group To Congress: Stop Online Advertisers In Their Tracks
- Microsoft, Intel Tout Their Collaboration On Windows 7
- Tech Data Adds Integration Services With New Center
| • |
| • |
| • |
| • |
| • |
| • |
| • |
|
|
