Firefox 0-day vulnerability in the wild

Talk about "WhatEVER !"..
Post Reply
Message
Author
Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2256
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

Firefox 0-day vulnerability in the wild

#1 Post by Puppy » Wed Nov 30, 2016 12:59 pm

https://www.wordfence.com/blog/2016/11/ ... -day-wild/
http://arstechnica.com/security/2016/11 ... d-in-2013/

- affects Firefox 41 to 50, incuding ESR and 50.0.1
- the exploit currently works on Windows only but other platforms are very likely affected as well
- it can run malicious code in context of logged user
- it is already being actively exploited, targets Tor (Firefox ESR based) browser
- the exploit code is disclosed so many other variants may already exists

The only workaround is to disable JavaScript or use another browser until fix is released.
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8

Puppy
Senior ThinkPadder
Senior ThinkPadder
Posts: 2256
Joined: Sat Oct 30, 2004 4:52 am
Location: Prague, Czech Republic

Re: Firefox 0-day vulnerability in the wild

#2 Post by Puppy » Wed Nov 30, 2016 5:13 pm

Fix is available, I strongly recommend to install it ASAP :!:

Firefox 50.0.2
Thunderbird 45.5.1
ThinkPad (1992 - 2012): R51, X31, X220, Tablet 8

dr_st
Senior ThinkPadder
Senior ThinkPadder
Posts: 6646
Joined: Sat Oct 29, 2005 6:20 am

Re: Firefox 0-day vulnerability in the wild

#3 Post by dr_st » Fri Dec 02, 2016 1:15 pm

Pale Moon apparently also includes a fix for said vulnerability (CVE-2016-9079) in 27.0.2:
http://www.palemoon.org/releasenotes.shtml
Current: X220 4291-4BG, T410 2537-R46, T60 1952-F76, T60 2007-QPG, T42 2373-F7G
Collectibles: T430s (IPS FHD + Classic Keyboard), X32 (IPS Screen)
Retired: X61 7673-V2V, A31p w/ Ultrabay Numpad
Past: Z61t 9440-A23, T60 2623-D3U, X32 2884-M5U

Saucey
Senior Member
Senior Member
Posts: 836
Joined: Tue Nov 06, 2012 9:22 pm
Location: San Diego, California
Contact:

Re: Firefox 0-day vulnerability in the wild

#4 Post by Saucey » Sun Dec 04, 2016 1:02 pm

Looks like I'll have to update Pale Moon then, thanks!
Incompitent(sp?) Electronic Recycler: caffeine addicted, techno blasting, ThinkPad hoarder.

Current: T430s, T431s, Pixel, MC207LL/A
Still around: X61T, A31p, T43p
Past: W700ds, X1C3, 701C, T60p

Summilux
Junior Member
Junior Member
Posts: 335
Joined: Fri Dec 24, 2010 8:02 am
Location: Paris (Latin Europe)

Re: Firefox 0-day vulnerability in the wild

#5 Post by Summilux » Mon Dec 05, 2016 8:43 pm

Thank you for the advices Puppy, I've updated both FF (just in case) and TB (used everyday).
Deathwisher
T60 2007-FSG (stolen)
X220 4287-CTO

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Off-Topic Stuff”

Who is online

Users browsing this forum: thinkpadcollection and 3 guests