<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Critical JavaScript vulnerability in Firefox 3.5</title>
	<atom:link href="http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/</link>
	<description></description>
	<lastBuildDate>Sat, 18 May 2013 08:51:04 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Brandon Sterne</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106069</link>
		<dc:creator>Brandon Sterne</dc:creator>
		<pubDate>Thu, 23 Jul 2009 23:30:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106069</guid>
		<description><![CDATA[@Russell

Yes, the fix was included in Firefox 3.5.1 which was release Thursday, July 16.  You should have received an update notification if you are running Firefox 3.5.]]></description>
		<content:encoded><![CDATA[<p>@Russell</p>
<p>Yes, the fix was included in Firefox 3.5.1 which was release Thursday, July 16.  You should have received an update notification if you are running Firefox 3.5.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Veditz</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106068</link>
		<dc:creator>Daniel Veditz</dc:creator>
		<pubDate>Thu, 23 Jul 2009 23:29:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106068</guid>
		<description><![CDATA[This was fixed in Firefox 3.5.1 which was released Thursday July 16.

http://www.mozilla.com/en-US/firefox/3.5.1/releasenotes/]]></description>
		<content:encoded><![CDATA[<p>This was fixed in Firefox 3.5.1 which was released Thursday July 16.</p>
<p><a href="http://www.mozilla.com/en-US/firefox/3.5.1/releasenotes/" rel="nofollow">http://www.mozilla.com/en-US/firefox/3.5.1/releasenotes/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russell Frank</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106067</link>
		<dc:creator>Russell Frank</dc:creator>
		<pubDate>Thu, 23 Jul 2009 23:19:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106067</guid>
		<description><![CDATA[It&#039;s been 9 days since this exploit was revealed.  Is there a fix yet?]]></description>
		<content:encoded><![CDATA[<p>It&#8217;s been 9 days since this exploit was revealed.  Is there a fix yet?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106026</link>
		<dc:creator>Peter</dc:creator>
		<pubDate>Sun, 19 Jul 2009 09:01:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106026</guid>
		<description><![CDATA[I&#039;ve looked all over the web today and yesterday and cannot find a decent explanation for why firefox 3.5.1 is running so slowly on my macbook (OSX 10.5)

It&#039;s not just loading pages where it&#039;s slow, it appears to hang for short periods (2-8 seconds) after clicking in the menu bar or any other sort of &quot;non-surfing&quot; command. It&#039;s a fresh install of 3.5.1 with no add-ons.

I am not finding the same sort of problem with safari or any other programs I&#039;m running and there is no obvious increase in CPU activity.

I am getting an &quot;unresponsive script&quot; window when loading my home page on facebook with the details:

&quot;Script: file:///Applications/Firefox.app/Contents/MacOS/components/nsProxyAutoConfig.js:133&quot;

I don&#039;t know if this is part of the problem. Any help would be appreciated. I don&#039;t want to go back to using Safari but at the moment Firefox is too slow to be usable.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve looked all over the web today and yesterday and cannot find a decent explanation for why firefox 3.5.1 is running so slowly on my macbook (OSX 10.5)</p>
<p>It&#8217;s not just loading pages where it&#8217;s slow, it appears to hang for short periods (2-8 seconds) after clicking in the menu bar or any other sort of &#8220;non-surfing&#8221; command. It&#8217;s a fresh install of 3.5.1 with no add-ons.</p>
<p>I am not finding the same sort of problem with safari or any other programs I&#8217;m running and there is no obvious increase in CPU activity.</p>
<p>I am getting an &#8220;unresponsive script&#8221; window when loading my home page on facebook with the details:</p>
<p>&#8220;Script: file:///Applications/Firefox.app/Contents/MacOS/components/nsProxyAutoConfig.js:133&#8243;</p>
<p>I don&#8217;t know if this is part of the problem. Any help would be appreciated. I don&#8217;t want to go back to using Safari but at the moment Firefox is too slow to be usable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ruth</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106025</link>
		<dc:creator>Ruth</dc:creator>
		<pubDate>Sun, 19 Jul 2009 01:17:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106025</guid>
		<description><![CDATA[Please help me: I installed 3.5 and I lost access to many sites -ex:Huffington Post, BBC, AND all help sites. I removed it but my Mac still thinks it is there and then I tried to install 3.0.11 but it would not open. It tells me Firefox is already open. What can I do? I have a Mac version 10.5.7. I am no programmer.]]></description>
		<content:encoded><![CDATA[<p>Please help me: I installed 3.5 and I lost access to many sites -ex:Huffington Post, BBC, AND all help sites. I removed it but my Mac still thinks it is there and then I tried to install 3.0.11 but it would not open. It tells me Firefox is already open. What can I do? I have a Mac version 10.5.7. I am no programmer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Concerned</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106024</link>
		<dc:creator>Concerned</dc:creator>
		<pubDate>Sat, 18 Jul 2009 23:44:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106024</guid>
		<description><![CDATA[Thanks for responding so quickly. I was just concerned as what I had read about the vulnerability on the site referenced in CVE-2009-2479 said:

&quot;By sending an overly long string of unicode data to the document.write method, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.&quot;

on another site:

&quot;Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions.&quot;

I&#039;m not familiar enough with firefox to know whether it really cannot be exploited to execute code or not.]]></description>
		<content:encoded><![CDATA[<p>Thanks for responding so quickly. I was just concerned as what I had read about the vulnerability on the site referenced in CVE-2009-2479 said:</p>
<p>&#8220;By sending an overly long string of unicode data to the document.write method, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.&#8221;</p>
<p>on another site:</p>
<p>&#8220;Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application. Failed attempts will likely result in denial-of-service conditions.&#8221;</p>
<p>I&#8217;m not familiar enough with firefox to know whether it really cannot be exploited to execute code or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Veditz</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106023</link>
		<dc:creator>Daniel Veditz</dc:creator>
		<pubDate>Sat, 18 Jul 2009 21:14:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106023</guid>
		<description><![CDATA[There is no evidence of a buffer overflow with milw0rm 9158 (CVE-2009-2479). It&#039;s an out-of-memory denial of service which would be nice to fix but doesn&#039;t warrant an emergency response.]]></description>
		<content:encoded><![CDATA[<p>There is no evidence of a buffer overflow with milw0rm 9158 (CVE-2009-2479). It&#8217;s an out-of-memory denial of service which would be nice to fix but doesn&#8217;t warrant an emergency response.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Concerned</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106022</link>
		<dc:creator>Concerned</dc:creator>
		<pubDate>Sat, 18 Jul 2009 19:44:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106022</guid>
		<description><![CDATA[Can we now have a fix to: CVE-2009-2479 ?

Mozilla Firefox 3.5 Unicode Data Remote Stack Buffer Overflow Vulnerability

Which still exists in version 3.5.1 afaik]]></description>
		<content:encoded><![CDATA[<p>Can we now have a fix to: CVE-2009-2479 ?</p>
<p>Mozilla Firefox 3.5 Unicode Data Remote Stack Buffer Overflow Vulnerability</p>
<p>Which still exists in version 3.5.1 afaik</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TL</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106021</link>
		<dc:creator>TL</dc:creator>
		<pubDate>Sat, 18 Jul 2009 01:43:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106021</guid>
		<description><![CDATA[For all those asking whether FF 3.5.1 fixes the problem and allows one to revert the change to JIT settings, see

http://www.mozilla.org/security/announce/2009/mfsa2009-41.html

which asserts that &quot;Users of Firefox 3.5 can avoid this vulnerability by disabling the Just-in-Time compiler as described in the Mozilla Security Blog. That workaround is not necessary in Firefox 3.5.1 and can be reverted.&quot;]]></description>
		<content:encoded><![CDATA[<p>For all those asking whether FF 3.5.1 fixes the problem and allows one to revert the change to JIT settings, see</p>
<p><a href="http://www.mozilla.org/security/announce/2009/mfsa2009-41.html" rel="nofollow">http://www.mozilla.org/security/announce/2009/mfsa2009-41.html</a></p>
<p>which asserts that &#8220;Users of Firefox 3.5 can avoid this vulnerability by disabling the Just-in-Time compiler as described in the Mozilla Security Blog. That workaround is not necessary in Firefox 3.5.1 and can be reverted.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Veditz</title>
		<link>http://blog.mozilla.org/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/comment-page-2/#comment-106020</link>
		<dc:creator>Daniel Veditz</dc:creator>
		<pubDate>Sat, 18 Jul 2009 01:42:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.org/security/?p=113#comment-106020</guid>
		<description><![CDATA[Firefox 3 and 3.5 do use /GS, /NXCOMPAT, and /DYNAMICBASE. Low Integrity Level is being worked on.]]></description>
		<content:encoded><![CDATA[<p>Firefox 3 and 3.5 do use /GS, /NXCOMPAT, and /DYNAMICBASE. Low Integrity Level is being worked on.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
