[ insider_reports_insider ] Mozilla Fixes Critical Firefox JavaScript Issue
David Utter Staff Writer
2008-04-17
Insider Reports RSS Feed
Garbage collection in the Firefox JavaScript engine caused browser crashes for some people.
 | | Mozilla Fixes Critical Firefox JavaScript Issue |  |
Firefox users recently witnessed an update for their browsers to version 2.0.0.14. This arrived on the heels of other security updates for the JavaScript engine used by the software.
Those security updates brought a stability problem to the JavaScript engine. When garbage collection runs, the issue caused some browsers to crash.
"We have no demonstration that this particular crash is exploitable but are issuing this advisory because some crashes of this type have been shown to be exploitable in the past," Mozilla said in its discussion of the fix.
Mac security not obscure: Security figures as one of Apple's big selling points in contrast with Microsoft Windows. It doesn't mean someone with an Apple logo on their laptop should ignore security for their machines.
ArsTechnica talked about securing Mac OS X in a guide on the topic. The first order of business: physical security.
"A firmware password prevents a user with physical access to the computer from starting up from an optical disk, a network boot volume, a separate drive connected in Target Disk Mode, or into single-user mode," the report said, in suggesting Mac users take advantage of the Open Firmware password feature that has been available since 2000.
A physical laptop lock securing the machine helps keep it out of the hands of an opportunistic thief. It only takes an unguarded moment for several thousand dollars of trendy Apple product to leave an office.
The guide also suggested some basic security measures like locking the desktop and using access control lists to manage multiple users on one machine. If this is starting to sound like work, it is; security is an ongoing trade-off of convenience and protection. That's why security pros get (or should get) the big bucks.
About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|