<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; firefox exploit</title>
	<atom:link href="http://www.ghacks.net/tag/firefox-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 23:31:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Critical Security Vulnerability In Firefox 3.5</title>
		<link>http://www.ghacks.net/2009/07/15/critical-security-vulnerability-in-firefox-3-5/</link>
		<comments>http://www.ghacks.net/2009/07/15/critical-security-vulnerability-in-firefox-3-5/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 12:01:02 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox exploit]]></category>
		<category><![CDATA[firefox patch]]></category>
		<category><![CDATA[firefox vulnerability]]></category>
		<category><![CDATA[mozilla-firefox]]></category>
		<category><![CDATA[security patch]]></category>
		<category><![CDATA[web browser]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=14412</guid>
		<description><![CDATA[A critical security vulnerability affecting Firefox 3.5 has been discovered and published on the security portal Milw0rm entitled Firefox 3.5 Heap Spray Vulnerability. A proof of concept exploit has been provided. In short, the vulnerability can lead to remote code execution. The good news is that a security patch has already been published by Mozilla [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/06/firefox.png" alt="firefox" title="firefox" width="128" height="128" class="alignleft size-full wp-image-13848" />A critical security vulnerability affecting <a href="http://www.ghacks.net/tag/firefox/">Firefox</a> 3.5 has been discovered and published on the security portal Milw0rm entitled Firefox 3.5 Heap Spray Vulnerability. A proof of concept exploit has been provided. In short, the vulnerability can lead to remote code execution. The good news is that a security patch has already been published by <a href="http://mozillalinks.org/wp/2009/07/mozilla-confirms-critical-security-flaw-in-firefox-3-5/">Mozilla Links</a>.</p>
<p>The security vulnerability can be fixed the following way. Type in about:config in the Firefox address bar and hit enter. Now filter for the term <strong>javascript.options.jit.content</strong> and double-click it afterwards to set it to false which disables the Tracemonkey JavaScript engine. This in turn could (and most likely will) reduce the JavaScript performance of the Firefox 3.5 web browser until an official security patch is provided by the <a href="http://www.ghacks.net/tag/firefox/">Mozilla Firefox</a> team.</p>
<p><span id="more-14412"></span>The security patch is expected to be released soon by the Firefox development team. Stay tuned, we keep you updated.</p>

	Tags: <a href="http://www.ghacks.net/tag/firefox/" title="firefox" rel="tag">firefox</a>, <a href="http://www.ghacks.net/tag/firefox-exploit/" title="firefox exploit" rel="tag">firefox exploit</a>, <a href="http://www.ghacks.net/tag/firefox-patch/" title="firefox patch" rel="tag">firefox patch</a>, <a href="http://www.ghacks.net/tag/firefox-vulnerability/" title="firefox vulnerability" rel="tag">firefox vulnerability</a>, <a href="http://www.ghacks.net/tag/mozilla-firefox/" title="mozilla-firefox" rel="tag">mozilla-firefox</a>, <a href="http://www.ghacks.net/tag/security-patch/" title="security patch" rel="tag">security patch</a>, <a href="http://www.ghacks.net/tag/web-browser/" title="web browser" rel="tag">web browser</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/" title="Latest Firefox Web Browser Vulnerable to 0-Day Exploit (March 26, 2009)">Latest Firefox Web Browser Vulnerable to 0-Day Exploit</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/03/27/web-browser-firefox-308/" title="Web Browser: Firefox 3.0.8 (March 27, 2009)">Web Browser: Firefox 3.0.8</a> (13)</li>
	<li><a href="http://www.ghacks.net/2009/03/13/web-browser-firefox-31-beta-3/" title="Web Browser: Firefox 3.1 Beta 3 (March 13, 2009)">Web Browser: Firefox 3.1 Beta 3</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/03/04/web-browser-firefox-307/" title="Web Browser: Firefox 3.0.7 (March 4, 2009)">Web Browser: Firefox 3.0.7</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/01/06/use-firefox-without-a-computer-mouse/" title="Use Firefox Without A Computer Mouse (January 6, 2009)">Use Firefox Without A Computer Mouse</a> (7)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/07/15/critical-security-vulnerability-in-firefox-3-5/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Latest Firefox Web Browser Vulnerable to 0-Day Exploit</title>
		<link>http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/</link>
		<comments>http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 14:32:58 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox 3]]></category>
		<category><![CDATA[firefox bu]]></category>
		<category><![CDATA[firefox exploit]]></category>
		<category><![CDATA[firefox security]]></category>
		<category><![CDATA[firefox vulnerability]]></category>
		<category><![CDATA[mozilla-firefox]]></category>
		<category><![CDATA[web browser]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/</guid>
		<description><![CDATA[Dante send me a tip about a 0-day exploit that is affecting the latest versions of the popular Firefox web browser. The exploit is described as a remote memory-corruption vulnerability that is affecting Firefox running on all supported operating systems. A proof of concept has been published by the security researcher and the Mozilla team [...]]]></description>
			<content:encoded><![CDATA[<p>Dante send me a tip about a 0-day exploit that is affecting the latest versions of the popular <a href="http://www.ghacks.net/tag/firefox/">Firefox</a> web browser. The exploit is described as a remote memory-corruption vulnerability that is affecting Firefox running on all supported operating systems. A proof of concept has been published by the security researcher and the Mozilla team has acknowledged the existence and announced plans to rush a Firefox 3.0.8 update at the beginning of next week.</p>
<p>The Firefox exploit could be used to add software to the target system without the knowledge of the users. There is currently no solution to block this attack from being executed other than being very careful about the visited websites. The safest would be to switch to another web browser at least for the time until the Mozilla developers have published the update that fixes the vulnerability in the web browser or a hot fix becomes known.</p>
<p>The issue has already been fixed <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=485217">according</a> to the bug report that was filed at the Mozilla website and is now awaiting verification. </p>
<p><span id="more-11482"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/firefox/" title="firefox" rel="tag">firefox</a>, <a href="http://www.ghacks.net/tag/firefox-3/" title="firefox 3" rel="tag">firefox 3</a>, <a href="http://www.ghacks.net/tag/firefox-bu/" title="firefox bu" rel="tag">firefox bu</a>, <a href="http://www.ghacks.net/tag/firefox-exploit/" title="firefox exploit" rel="tag">firefox exploit</a>, <a href="http://www.ghacks.net/tag/firefox-security/" title="firefox security" rel="tag">firefox security</a>, <a href="http://www.ghacks.net/tag/firefox-vulnerability/" title="firefox vulnerability" rel="tag">firefox vulnerability</a>, <a href="http://www.ghacks.net/tag/mozilla-firefox/" title="mozilla-firefox" rel="tag">mozilla-firefox</a>, <a href="http://www.ghacks.net/tag/web-browser/" title="web browser" rel="tag">web browser</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/03/27/web-browser-firefox-308/" title="Web Browser: Firefox 3.0.8 (March 27, 2009)">Web Browser: Firefox 3.0.8</a> (13)</li>
	<li><a href="http://www.ghacks.net/2009/03/04/web-browser-firefox-307/" title="Web Browser: Firefox 3.0.7 (March 4, 2009)">Web Browser: Firefox 3.0.7</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/07/15/critical-security-vulnerability-in-firefox-3-5/" title="Critical Security Vulnerability In Firefox 3.5 (July 15, 2009)">Critical Security Vulnerability In Firefox 3.5</a> (10)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/mozilla-firefox-3-0-11-released/" title="Mozilla Firefox 3.0.11 Released (June 11, 2009)">Mozilla Firefox 3.0.11 Released</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/09/09/firefox-3-5-3/" title="Firefox 3.5.3 (September 9, 2009)">Firefox 3.5.3</a> (11)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
