By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Okay News
  • News
  • Entertainment
  • Business & Economy
  • Sport
  • Tech
Font ResizerAa
Okay NewsOkay News
Search
  • News
  • Entertainment
  • Business & Economy
  • Sport
  • Tech
Follow US
FeaturedTech

High Vulnerability Detected In Mozilla Firefox. (Patch Released).

Damilola A.
By
Damilola A.
ByDamilola A.
Entertainment News Reporter
Damilola is a dedicated entertainment writer for Okay Nigeria (Okay.ng). He joined the platform with the aim of using his experience in the Entertainment industry to...
Follow:
Published: 2015/08/10
2 Min Read
Share
SHARE

firefox_changed_ui

Mozilla is warning users about a vulnerability in its Firefox Web browser that could allow attackers to steal information from their computer. The browser-maker urges users to update Firefox to the latest available version — v39.0.3 or above – to protect their system from the said vulnerability.

While by default Firefox automatically updates itself, those who have the setting off will have to manually update via the ‘About Firefox’ setting in the Help tab. Earlier this week, the company was notified by security researcher Cody Crews about a malicious ad on a Russian news portal that was exploiting a vulnerability in Firefox’s PDF Viewer, a built-in feature. The exploit seeks sensitive files on the victim’s computer and uploads it to a suspicious server reportedly located in Ukraine.

Versions of Firefox that don’t support PDF Viewer including Firefox for Android client aren’t vulnerable to the exploit. Firefox’s Mac client is also not affected. “The vulnerability comes from the interaction of the mechanism that enforces JavaScript context separation (the ‘same origin policy’) and Firefox’s PDF Viewer,” wrote Mozilla security chief Daniel Veditz.

“The vulnerability does not enable the execution of arbitrary code but the exploit was able to inject a JavaScript payload into the local file context. This allowed it to search for and upload potentially sensitive local files.”

In the blog post, Veditz also notes that the exploit looks for subversion, s3browser, Firezilla, and libpurple configuration files on the Windows systems. On Linux, the payload checks global configuration files in the /etc directory. It also looks into .bashhistory, .mysqlhistory, .pgsql_history, and .ssh configuration files and keys.

Veditz says that people who use ad-blocking tools might not be affected with the vulnerability either, though it isn’t too sure about that. Regardless, you would want to update your Firefox Web browser to the latest version.

TAGGED:mozillaa vulnerabilitypatch
Share This Article
Facebook Pinterest Whatsapp Whatsapp Email Print
ByDamilola A.
Entertainment News Reporter
Follow:
Damilola is a dedicated entertainment writer for Okay Nigeria (Okay.ng). He joined the platform with the aim of using his experience in the Entertainment industry to share wonderful articles in this field. Dammy is a die-hard fan of Wizkid.
Previous Article 14 Dead In Abakaliki Road Accident.
Next Article Twitter Unveils New Smileys For English Premier League.

Stay Connected

FacebookLike
XFollow
InstagramFollow
TiktokFollow
WhatsAppFollow

You Might Also Like

Nigerian Communications Commission (NCC)
Tech

NCC Emerges Among Top Three Federal Agencies for Website Performance in 2025

By
Yusuf Abubakar
5 Min Read
Artificial intelligence (AI)International

Authors Sue Meta, OpenAI, xAI, Others Over Alleged Piracy of Books

By
Adamu Abubakar Isa
2 Min Read
Featured

TikTok Brings Nollywood, Digital Creators Together at Lagos #WhatToWatch Cinema Experience

By
Okay News
4 Min Read
Okay NewsOkay News
© Okay International Limited - All rights reserved
  • About Us
  • Advertising
  • Contact
  • Careers
  • Team
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Continue with Facebook
Not a member? Sign Up