Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Mozilla Firefox - IDN Patch corrects critical vulnerabilities

  One day after public disclosure of the vulnerability, an XPI patch was provided that deactivates IDN processing. This tested out well for me 

Mozilla Firefox - IDN Patch corrects critical vulnerabilities
https://addons.mozilla.org/messages/307259.html

On September 9, the Mozilla team released a configuration change which, as a temporary measure to work around this problem, disables IDN in the browser. IDN functionality will be restored in a future product update. The fix is either a manual configuration change or a small download which will make this configuration change for the user.

I actually prefer using the manual approach as it's easy and expedient to perform, plus you don't have to toggle back on the “allow software to be installed from a website“ (which typically should be set to off as a best practice)

MANUAL APPROACH:

1. You can type "about:config" as a "URL" in the address bar
2. Then key or locate "network:enableIDN"
3. Double click it to disable it (set it to "false")
4. Close and restart browser (you can do another about:config to confirm this is now set as false)