Bugs are a fact of life in the technology world, and the Open Source community is no exception. What is exceptional, however, is the open way these vulnerabilities are handled, as the developers behind Mozilla's Firefox browser have aptly demonstrated.
One element of the acclaimed performance booster is giving its developers something of a headache this week, however. The first zero-day exploit for Firefox 3.5 was revealed publicly on Monday, in the form of a vulnerability in the browser's Just-in-time compiler. Unlike older methods of execution, which interpret the bytecode created from the browser's source code, a Just-in-time compiler transforms the bytecode into native machine code just before executing it, resulting in significant performance improvements. Attackers can utilize the vulnerability to execute malicious code on the user's system by luring them to a website containing the exploit code.
A patch for the exploit has yet to be released, though Firefox developers are on the case. Mozilla has indicated that once developers have prepared and tested the patch, it will be pushed out to users via the normal update channels. Linux users may wish to make special note of the update — because it was released so recently, users are likely to have installed Firefox 3.5 manually rather than via their distribution's repositories, and thus may not receive updates in the manner they are accustomed to.
Developers stress that this is only a temporary fix, and as it will result in significantly decreased browser performance, should be returned to its original setting as soon as the patch is installed. Users uncomfortable with altering about:config settings can achieve the same result by running the browser in Safe Mode, though this will result in additional components being disabled.
Justin Ryan is a Contributing Editor for Linux Journal.
- Readers' Choice Awards 2013
- New Products
- Two Pi R
- The Geek's Guide to the Coolest 2013 Holiday Gifts
- Non-Linux FOSS: Let's Make Music Together
- Best. Cake. Ever.
- A Handy U-Boot Trick
- AIDE—Developing for Android on Android
- Raspberry Pi: the Perfect Home Server
- Tech Tip: Really Simple HTTP Server with Python
4 hours 25 min ago
20 hours 31 min ago
- Thanks for clearing that up.
1 day 1 hour ago
- Nice coding on the cake. I
1 day 13 hours ago
- Baker's identity
1 day 18 hours ago
- Uber jealous
1 day 23 hours ago
- Reality is disapointing
2 days 9 hours ago
- Máy sấy quần áo
2 days 12 hours ago
- Services on GlusterFS
2 days 12 hours ago
- Reply to comment | Linux Journal
2 days 14 hours ago