WXforum.net
May 21, 2013, 09:15:59 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
Members: 6617  •  Posts: 178523  •  Topics: 18115
Please welcome TheMOX, our newest member.
Welcome to the the new hosting for WXforum.net.
 
   Home   Help Search Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Firefox 3.5 JavaScript 0-day vulnerability + Microsoft OfficeWeb ActiveX patch  (Read 1549 times)
0 Members and 1 Guest are viewing this topic.
saratogaWX
Administrator
Forecaster
*****
Online Online

Posts: 3729


Saratoga, CA, USA Weather - free PHP scripts


WWW
« on: July 15, 2009, 04:48:27 PM »

As reported in various security postings, there's a vulnerability in Firefox 3.5 in processing JavaScript that is yet unpatched, and exploit code has been posted.

See http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html for more info.

Meanwhile, I suggest that you follow Brian Krebs instructions below to mitigate this (if you are a Firefox 3.5 user)

Quote
Fortunately, there is a relatively easy fix for this that can be reversed once Mozilla issues a patch.
To disable the vulnerable component, open up a new Firefox window and type "about:config" (without the quotes) in the browser's address bar.
In the "filter" box, type "jit" and you should see a setting called "javascript.options.jit.content".
You should notice that beside that setting it reads "true," meaning the setting is enabled.
If you just double-click on that setting, it should disable it, changing the option to "false." That's it.

Note that making this change will slow down Javascript rendering in Firefox 3.5 to 3.0 speeds, but that may be a worthwhile trade-off for readers concerned about the availability of exploit code for this flaw.

Not to be outdone, Microsoft issued an update of Killbits to fix an IE ActiveX vulnerability that had active exploit code in the wild.  That fix is available on Microsoft/Windows Update.

Lets be careful out there...

Best regards,
Ken

Logged

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis Vantage Pro Plus - FARS, Boltek-PCI/NexStorm, GRLevel3, WD, WL, VWS, Cumulus, Meteohub
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP
Cienega32
Forecaster
*****
Offline Offline

Posts: 2307



WWW
« Reply #1 on: July 16, 2009, 01:39:28 AM »

Nice - thank you, Sir!
Logged


Pat ~ Davis VP2 6153-Weatherlink-Weather Display-StartWatch-VirtualVP-WinXP Pro-SP3
www.LasCruces-Weather.com   www.EastMesaWeather.com
port1
Forecaster
*****
Offline Offline

Posts: 667




« Reply #2 on: July 16, 2009, 02:18:10 AM »

Thanks, Ken.  Smile
Always good to have you watching our backs...especially us FireFox users.
Much obliged, sir!  Applause

Henry
Logged

KNYFLORA5
WMR968
VWS v14.00 p73
CoCoRaHS NY-NS-7
CWOP DW1891
SKYWARN 09-148
saratogaWX
Administrator
Forecaster
*****
Online Online

Posts: 3729


Saratoga, CA, USA Weather - free PHP scripts


WWW
« Reply #3 on: July 16, 2009, 11:20:11 AM »

You're welcome!

Active exploit (via SQL Injection attack) for the Microsoft vulnerability in OWC (ActiveX control) is in the wild now according to SANS Incident Center.  Make sure you've run Microsoft/Windows Update on your XP/Vista systems.

Edit: sorry.. had wrong link for SANS.  Now corrected.
« Last Edit: July 16, 2009, 01:11:08 PM by saratogaWX » Logged

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis Vantage Pro Plus - FARS, Boltek-PCI/NexStorm, GRLevel3, WD, WL, VWS, Cumulus, Meteohub
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP
port1
Forecaster
*****
Offline Offline

Posts: 667




« Reply #4 on: July 16, 2009, 06:04:19 PM »

Did the Windows update too.
Thanks! Cool

Henry
Logged

KNYFLORA5
WMR968
VWS v14.00 p73
CoCoRaHS NY-NS-7
CWOP DW1891
SKYWARN 09-148
Mark / Ohio
Live from Mars!
Forecaster
*****
Offline Offline

Posts: 2351



WWW
« Reply #5 on: July 16, 2009, 10:03:10 PM »

Thanks Ken for the heads up.   Very Happy

Just made the changes on my laptop and run windows update last night on it.  Sounds like I should break down and reboot and patch the ole weather computer in the near future as well.
Logged

Mark 
2002 Davis VP I Wireless, WeatherLink (Serial), VWS, ImageSalsa, GRLevel3, VirtualVP, VPLive, StartWatch, Windows XP (SP3)

TorH
Forecaster
*****
Offline Offline

Posts: 405



WWW
« Reply #6 on: July 17, 2009, 04:25:07 AM »

I got my machines updated here, the killbits update came automatic for a few days ago here along with some others updates.
I always has the automatic updates on, to download, but to ask for installing. Then i have a little control over the updates from MS  Neutral

Better safe, than sorry!
Logged

Davis Vantage PRO2 wireless
VWS V14.00 p103, WD ver.10.37N, WL 5.8.2, VVP.
WeatherFlash
DW1549
WeatherUnderground: INORDLAN14
Location: Fauske, Northern Norway. N 67°15'41", E 15°24'41"
http://bjornli.net                     
ncpilot
Forecaster
*****
Offline Offline

Posts: 920


WWW
« Reply #7 on: July 17, 2009, 09:20:12 AM »

Mozilla issued a patch yesterday...

http://news.cnet.com/8301-1009_3-10289205-83.html?tag=newsEditorsPicksArea.0

Logged

Marc
Wilmington, NC
"Monkey Junction Weather"
Davis VP2 wireless, WeatherLink
saratogaWX
Administrator
Forecaster
*****
Online Online

Posts: 3729


Saratoga, CA, USA Weather - free PHP scripts


WWW
« Reply #8 on: July 17, 2009, 11:31:30 AM »

And issued an update to Firefox 3.5.1 -- just use Help, Check for updates... to do the update.

After that, you can reverse the tweak in the first post to re-enable the JIT JavaScript function with it's improved performance.

about:config
search for jit
Doubleclick on the 'false' for javascript.options.jit.content (so it changes to 'true' again)

Best regards,
Ken

ref: http://www.mozilla.org/security/announce/2009/mfsa2009-41.html
« Last Edit: July 17, 2009, 11:36:02 AM by saratogaWX » Logged

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis Vantage Pro Plus - FARS, Boltek-PCI/NexStorm, GRLevel3, WD, WL, VWS, Cumulus, Meteohub
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP
Garth Bock
Bloomington, Illinois Weather
Forecaster
*****
Offline Offline

Posts: 1622


I went dark to protest SOPA


WWW
« Reply #9 on: July 17, 2009, 02:49:48 PM »

All the kiddie techs here at work were all enthused about 3.5 and I told them being new it might be good to wait awhile before recommending it to anyone at the university. I am still on 2.0. When I showed them the link about the vulnerability, they were all surprise. 
Logged


Davis VPro2,VWS,WL,VVP,WD,WDL,Cumulus,WV32,VPLive
sam2004gp
Mount Crawford, Virginia
Forecaster
*****
Offline Offline

Posts: 2782


Weeeeeeeee!!!!


WWW
« Reply #10 on: July 17, 2009, 06:51:40 PM »

Just installed the FF 3.5.1 update, I bet that fixes the vulnerability.
Logged

SAM --->>> http://www.mountcrawfordweather.org
OS WMR-968 with a Dedicated PWS Weather Computer running VWS v13.01 p09

SlowModem
Forecaster
*****
Offline Offline

Posts: 4505


WX @ 26.4 kbs


WWW
« Reply #11 on: July 17, 2009, 07:00:44 PM »

Just installed the FF 3.5.1 update, I bet that fixes the vulnerability.

So how does one prove a negative?  If it never happens, is it because of the fix?

 Rolling Eyes
Logged

Greg Whitehead
Ten Mile, TN

http://wattsbarweather.net

SlowModem
Forecaster
*****
Offline Offline

Posts: 4505


WX @ 26.4 kbs


WWW
« Reply #12 on: July 18, 2009, 01:24:59 AM »

Just installed the FF 3.5.1 update, I bet that fixes the vulnerability.

So how does one prove a negative?  If it never happens, is it because of the fix?

 Rolling Eyes

That about:config is a scary place.  It seems a person could really screw things up there if they tinkered too much in there.

Logged

Greg Whitehead
Ten Mile, TN

http://wattsbarweather.net

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.123 seconds with 19 queries.
anything