{"id":386,"date":"2010-10-26T14:30:24","date_gmt":"2010-10-26T21:30:24","guid":{"rendered":"http:\/\/blog.mozilla.org\/security\/?p=386"},"modified":"2010-10-27T22:23:02","modified_gmt":"2010-10-28T05:23:02","slug":"critical-vulnerability-in-firefox-3-5-and-firefox-3-6","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/","title":{"rendered":"Critical vulnerability in Firefox 3.5 and Firefox 3.6"},"content":{"rendered":"<p style=\"padding-left: 30px;\"><strong>Update <\/strong>(Oct 27, 2010 @ 20:12)<strong>:<\/strong><br \/>\nA fix for this vulnerability has been released for Firefox and Thunderbird users.<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"https:\/\/developer.mozilla.org\/devnews\/index.php\/2010\/10\/27\/firefox-3-6-12-and-3-5-15-security-updates-now-available\/\">Firefox 3.6.12 and 3.5.15 security updates now available<\/a><br \/>\n<a href=\"https:\/\/developer.mozilla.org\/devnews\/index.php\/2010\/10\/27\/thunderbird-3-1-6-and-3-0-10-security-updates-now-available\/\">Thunderbird 3.1.6 and 3.0.10 security updates now available<\/a><\/p>\n<p><strong>Issue:<\/strong><br \/>\nMozilla is aware of a critical vulnerability affecting Firefox 3.5 and Firefox 3.6 users.  We have received reports from several security research firms that exploit code leveraging this vulnerability has been detected in the wild.<\/p>\n<p><strong>Impact to users:<\/strong><br \/>\nUsers who visited an infected site could have been affected by the malware through the vulnerability. The trojan was initially reported as live on the Nobel Peace Prize site, and that specific site is now being blocked by Firefox&#8217;s built-in malware protection.  However, the exploit code could still be live on other websites.<\/p>\n<p><strong>Status:<\/strong><br \/>\nWe have diagnosed the issue and are currently developing a fix, which will be pushed out to Firefox users as soon as the fix has been properly tested.<\/p>\n<p>In the meantime, users can protect themselves by doing either of the following:<\/p>\n<ul>\n<li><a href=\"http:\/\/support.mozilla.com\/en-US\/kb\/JavaScript#Enabling_and_disabling_JavaScript\">Disabling JavaScript<\/a> in Firefox<\/li>\n<li>Using the <a href=\"https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/722\/\">NoScript<\/a> Add-on<\/li>\n<\/ul>\n<p><strong>Credit:<\/strong><br \/>\nMorten Kr\u00e5kvik of Telenor SOC<\/p>\n<p>&#8212;<br \/>\nBrandon Sterne<br \/>\nMan-in-the-middle<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Update (Oct 27, 2010 @ 20:12): A fix for this vulnerability has been released for Firefox and Thunderbird users. Firefox 3.6.12 and 3.5.15 security updates now available Thunderbird 3.1.6 and &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/\">Read more<\/a><\/p>\n","protected":false},"author":54,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[69],"tags":[73],"coauthors":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Critical vulnerability in Firefox 3.5 and Firefox 3.6 - Mozilla Security Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Al Billings\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/\",\"name\":\"Critical vulnerability in Firefox 3.5 and Firefox 3.6 - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"datePublished\":\"2010-10-26T21:30:24+00:00\",\"dateModified\":\"2010-10-28T05:23:02+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/d33dd2d17a8109165b6df7d1245e33fc\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Critical vulnerability in Firefox 3.5 and Firefox 3.6\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/d33dd2d17a8109165b6df7d1245e33fc\",\"name\":\"Al Billings\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/9456a97c7c46aaacc293dfb3e668ecfd\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/59eb615338adae529ebe54960f87cd0c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/59eb615338adae529ebe54960f87cd0c?s=96&d=identicon&r=g\",\"caption\":\"Al Billings\"},\"sameAs\":[\"https:\/\/openbuddha.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Critical vulnerability in Firefox 3.5 and Firefox 3.6 - Mozilla Security Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/","twitter_misc":{"Written by":"Al Billings","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/","url":"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/","name":"Critical vulnerability in Firefox 3.5 and Firefox 3.6 - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"datePublished":"2010-10-26T21:30:24+00:00","dateModified":"2010-10-28T05:23:02+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/d33dd2d17a8109165b6df7d1245e33fc"},"breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2010\/10\/26\/critical-vulnerability-in-firefox-3-5-and-firefox-3-6\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"Critical vulnerability in Firefox 3.5 and Firefox 3.6"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/d33dd2d17a8109165b6df7d1245e33fc","name":"Al Billings","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/9456a97c7c46aaacc293dfb3e668ecfd","url":"https:\/\/secure.gravatar.com\/avatar\/59eb615338adae529ebe54960f87cd0c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/59eb615338adae529ebe54960f87cd0c?s=96&d=identicon&r=g","caption":"Al Billings"},"sameAs":["https:\/\/openbuddha.com"]}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/386"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/54"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=386"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/386\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=386"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}