Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

TexasTowelie

(112,249 posts)
Sat Aug 8, 2015, 06:56 AM Aug 2015

Update Firefox now! Fix rushed out for an exploit that steals files off your hard drive

Late Thursday night, Mozilla released a security patch for the Firefox browser after finding a serious vulnerability being exploited in the wild. The vulnerability allows malicious attackers to use some JavaScript magic to “search for and upload potentially sensitive” from your hard drive to their servers.

Mozilla is asking all Firefox users to upgrade immediately to version 39.0.3. Anyone on the Firefox Extended Support release via their school or business should upgrade to version 38.1.1.

The security issue only affects PCs since the flaw relies on an interaction between Firefox’s PDF Viewer and other parts of the browser. Firefox for Android does not have the PDF Viewer and therefore not vulnerable, according to a blog post by Mozilla’s security lead, Daniel Veditz.

Mozilla first became aware of the flaw after a Firefox user noticed that an ad embedded on a Russian news site was using an exploit to search for sensitive files. The malware would then upload the sensitive files to a server in the Ukraine. This all appears to happen in the background with the user none the wiser. The malware also leaves no trace it was ever on your machine.

Read more: http://www.pcworld.com/article/2960789/browsers/update-firefox-now-fix-rushed-out-for-an-exploit-that-steals-files-off-your-hard-drive.html

5 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Update Firefox now! Fix rushed out for an exploit that steals files off your hard drive (Original Post) TexasTowelie Aug 2015 OP
I wonder if the Russian news site is one of those that certain posters link to all the time. hobbit709 Aug 2015 #1
I'm up to 39.0.3 Downwinder Aug 2015 #2
How does one tell what version one has? passnobuck Aug 2015 #3
Click the menu icon top right SwankyXomb Aug 2015 #4
Thanks for the message passnobuck Aug 2015 #5

SwankyXomb

(2,030 posts)
4. Click the menu icon top right
Sat Aug 8, 2015, 12:57 PM
Aug 2015

That's the three lines, then the ? for the help menu, then About Firefox.

Latest Discussions»Help & Search»Computer Help and Support»Update Firefox now! Fix r...