By using this site, you agree to the Privacy Policy and Terms & Conditions.
Accept
Okay.ngOkay.ngOkay.ng
Font ResizerAa
  • News
    • Politics
  • Entertainment
  • Business & Economy
  • Sport
  • Tech
Reading: High Vulnerability Detected In Mozilla Firefox. (Patch Released).
Share
Font ResizerAa
Okay.ngOkay.ng
  • News
  • Entertainment
  • Business & Economy
  • Sport
  • Tech
Search
  • News
    • Politics
  • Entertainment
  • Business & Economy
  • Sport
  • Tech
Follow US
  • About Okay.ng
  • Advertising on Okay.ng
  • Contact Okay.ng
  • Careers
  • Meet the Team behind Okay.ng
  • Ownership and Funding of Okay.ng
  • Editorial Principles at Okay.ng
© OKN MEDIA PUBLISHING 2022 - All rights reserved
FeaturedTech

High Vulnerability Detected In Mozilla Firefox. (Patch Released).

Damilola A.
By Damilola A.
Published: August 10, 2015
Share
2 Min Read
SHARE

firefox_changed_ui

Mozilla is warning users about a vulnerability in its Firefox Web browser that could allow attackers to steal information from their computer. The browser-maker urges users to update Firefox to the latest available version — v39.0.3 or above – to protect their system from the said vulnerability.

While by default Firefox automatically updates itself, those who have the setting off will have to manually update via the ‘About Firefox’ setting in the Help tab. Earlier this week, the company was notified by security researcher Cody Crews about a malicious ad on a Russian news portal that was exploiting a vulnerability in Firefox’s PDF Viewer, a built-in feature. The exploit seeks sensitive files on the victim’s computer and uploads it to a suspicious server reportedly located in Ukraine.

Versions of Firefox that don’t support PDF Viewer including Firefox for Android client aren’t vulnerable to the exploit. Firefox’s Mac client is also not affected. “The vulnerability comes from the interaction of the mechanism that enforces JavaScript context separation (the ‘same origin policy’) and Firefox’s PDF Viewer,” wrote Mozilla security chief Daniel Veditz.

- Advertisement -

“The vulnerability does not enable the execution of arbitrary code but the exploit was able to inject a JavaScript payload into the local file context. This allowed it to search for and upload potentially sensitive local files.”

In the blog post, Veditz also notes that the exploit looks for subversion, s3browser, Firezilla, and libpurple configuration files on the Windows systems. On Linux, the payload checks global configuration files in the /etc directory. It also looks into .bashhistory, .mysqlhistory, .pgsql_history, and .ssh configuration files and keys.

Veditz says that people who use ad-blocking tools might not be affected with the vulnerability either, though it isn’t too sure about that. Regardless, you would want to update your Firefox Web browser to the latest version.

Stay Updated on the Go with Our Latest News—Join Our WhatsApp Channel Now!
TAGGED:mozillaa vulnerabilitypatch
Share This Article
Facebook Whatsapp Whatsapp Telegram Email Copy Link Print
ByDamilola A.
Entertainment News Reporter
Follow:
Damilola is a dedicated entertainment writer for Okay Nigeria (Okay.ng). He joined the platform with the aim of using his experience in the Entertainment industry to share wonderful articles in this field. Dammy is a die-hard fan of Wizkid.
Previous Article 14 Dead In Abakaliki Road Accident.
Next Article Twitter Unveils New Smileys For English Premier League.

Connect with Okay on Social

FacebookLike
XFollow
InstagramFollow
TelegramFollow
- Advertisement -
Ad imageAd image
- Advertisement -
- Advertisement -
Ad imageAd image

Recent Posts

Delta Governor: Defection to APC Aimed at Advancing State, Not Weakening PDP
Politics
Tinubu to Attend Pope Leo XIV’s Inauguration in Rome
News
VeryDarkMan
Police Re-arraign VDM Over Cyberbullying Allegations Against Nollywood Actresses, Others
News
JUST IN: House of Reps Advances Bill to Make Voting Mandatory
News Top stories
Panic in Ondo as Two-Month-Old Baby Disappears
News
- Advertisement -
Ad imageAd image

You May Also Like

Brands

Nestlé Empowers Over 300 Youths in Lagos Through MYOWBU Entrepreneurship Workshop

Yusuf Abubakar
Yusuf Abubakar
May 15, 2025
News

EFCC Removes Foreign National Elie Bitar from Wanted List Over CBEX Fraud Allegations

Muhammad A. Aliyu
Muhammad A. Aliyu
May 15, 2025
Sport

Nottingham Forest’s Taiwo Awoniyi Wakes from Induced Coma, Recovering After Emergency Surgery

Muhammad A. Aliyu
Muhammad A. Aliyu
May 15, 2025
Okay.ngOkay.ng
Follow US
© OKN MEDIA PUBLISHING 2025 - All rights reserved
  • About Okay.ng
  • Advertising on Okay.ng
  • Contact Okay.ng
  • Careers
  • Meet the Team behind Okay.ng
  • Ownership and Funding of Okay.ng
  • Editorial Principles at Okay.ng
adbanner
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?