Full Disclosure mailing list archives

Re: Firefox 0.92 DoS via TinyBMP


From: Thomas Kaschwig <sec () kaschwig net>
Date: Mon, 12 Jul 2004 15:19:25 +0200

Hi,

thE_iNviNciblE wrote:

there is a security vulnerability in Firebox 0.92 (latest Version)

http://www.4rman.com/exploits/tinybmp.htm

this link causes that your virutal memory will be rise up 1,2 GB used
Memory...

There is no such effect with Firefox 0.9.1 on Linux, the virtual memory 
for `fixefox-bin' goes only up to 76MB. It seems to be an Windows-only 
exploit.

Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7) Gecko/20040626 
Firefox/0.9.1

Thomas
-- 
PGP/GnuPG: http://www.kaschwig.net/kaschwig.gpg.asc * KeyID: 0x3D68D63A
Fingerprint: 274A 4CB8 B362 D593 39D6 0989 8FC3 725F 3D68 D63A
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: