Full Disclosure mailing list archives

Re: Flaw in Firefox 2.0 RC2


From: "Tyop?" <tyoptyop () gmail com>
Date: Wed, 25 Oct 2006 21:24:32 +0200

On 10/20/06, Jure Pečar <pegasus () nerv eu org> wrote:
On Thu, 19 Oct 2006 13:05:48 -0400
Mark A Basil <mark.basil () markmonitor com> wrote:
On Wed, 2006-10-18 at 10:28 +1000, jm wrote:
Firefox 1.5.07 on CentOS died quite nicely too.
Mike () gmail com wrote:
http://lcamtuf.coredump.cx/ffoxdie.html
this exploit still works with the latest Firefox 2.0 RC3
It is also affecting any browser using the Gecko rendering engine
(gecko-1.8 at least), such as Epiphany and Galeon, and not restricted to
'Firefox'.
Also renders Opera 9.02 (build 434) on linux unresponsive at 100% cpu usage.

Netcat 0.7.1 isn't affected on FreeBSD 7.0.

-- 
Tyop?
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: