oss-sec mailing list archives

Re: CVE request: firefox 2.0.14 ( Crash in JavaScript garbage collector)


From: Hanno Böck <hanno () hboeck de>
Date: Thu, 17 Apr 2008 19:00:37 +0200

Am Donnerstag 17 April 2008 schrieb Steven M. Christey:
On Thu, 17 Apr 2008, Hanno [utf-8] Böck wrote:
And again, are pure browser crashers considered security relevant?

CVE chooses to include them because:

Ok, then please include this one:
http://www.securityfocus.com/bid/27243
http://hboeck.de/archives/578-How-long-does-it-take-to-fix-a-crash-bug.html
http://sam.zoy.org/blog/2007-01-16-exposing-file-parsing-vulnerabilities

for firefox (lol-firefox.gif crash).

-- 
Hanno Böck              Blog:           http://www.hboeck.de/
GPG: 3DBD3B20           Jabber/Mail:    hanno () hboeck de

Attachment: signature.asc
Description: This is a digitally signed message part.


Current thread: