Full Disclosure mailing list archives

Re: AW: Firefox 0.92 DoS via TinyBMP


From: Lee Packham <lpackham () gmail com>
Date: Mon, 12 Jul 2004 20:12:54 +0100

I can confirm it too... How bizarre. However, i've closed it, and the
Commit Charge in Windows is still up at 1851MB! It only clears when
you close the firefox process completely (as expected).

On Mon, 12 Jul 2004 14:53:37 +0200, Webmaster
<webmaster () domina-chantal de> wrote:
Hi,

i can confirm it for FF 0.92 on afully Patched WindowsBox...

but it doesn't happen much...memory increases to 1,8GB but the Pc is still
acting normal, nothing is slowed down or something...

just closed it and the memory goes back to normal...

Grettings,
-Ron

-----Ursprungliche Nachricht-----
Von: full-disclosure-admin () lists netsys com
[mailto:full-disclosure-admin () lists netsys com]Im Auftrag von
thE_iNviNciblE
Gesendet: Montag, 12. Juli 2004 13:24
An: Full-Disclosure () lists netsys com
Betreff: [Full-Disclosure] Firefox 0.92 DoS via TinyBMP

Hi,

there is a security vulnerability in Firebox 0.92 (latest Version)

http://www.4rman.com/exploits/tinybmp.htm

this link causes that your virutal memory will be rise up 1,2 GB used
Memory...

maybe Thunderbird 0.72 is also vulnerable via HTML.

credits to: StupidWhiteMan

--
   Best Regard thE_iNviNciblE
   ---------------------------
   Wissen ist Macht

Freie Meinung: http://www.your-mind-is-free.de.vu
IT-Security  : http://www.kid2elite.de.vu
IT-Forum     : http://www.security-focus.de.vu

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: