Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - iDEFENSE Security Advisory 02.28.05: Mozilla Firefox and,MozillaBrowser Out Of Memory Heap Corruption Design Error

 
Thread Tools Search this Thread
Old 03-02-2005, 12:46 AM   #1
Default iDEFENSE Security Advisory 02.28.05: Mozilla Firefox and,MozillaBrowser Out Of Memory Heap Corruption Design Error


FIX: UPGRADE FIREFOX 1.01 posted at firefox site.

http://www.idefense.com/application/...status=fa lse

The article indicates there are no currently know work arounds.

Thought folks here would find this interesting.

CAN-2005-0255

http://cve.mitre.org/cgi-bin/cvename...=CAN-2005-0255

Mozilla indicates the likelihood of a working exploit is minimal:

http://www.mozilla.org/security/anno...sa2005-18.html

Mozilla indicates version 1.01 is not vulnerable.

I thought folks might be interested. I would upgrade, while I
understand the complexity of the exploit (ie injecting code at the fail
point when memory heap is exhausted) a failed attempt would crash the
browser. I would prefer my browser, or anything else, don't crash. I
wouldn't be surprised to see the bad guys crash the browser just to be
rude to those refusing their play toys.

Winged


winged
  Reply With Quote
Old 03-02-2005, 01:56 AM   #2
winged
 
Posts: n/a
Default Re: iDEFENSE Security Advisory 02.28.05: Mozilla Firefox and,Mozilla
winged wrote:
> FIX: UPGRADE FIREFOX 1.01 posted at firefox site.
>
> http://www.idefense.com/application/...status=fa lse
>
>
> The article indicates there are no currently know work arounds.
>
> Thought folks here would find this interesting.
>
> CAN-2005-0255
>
> http://cve.mitre.org/cgi-bin/cvename...=CAN-2005-0255
>
> Mozilla indicates the likelihood of a working exploit is minimal:
>
> http://www.mozilla.org/security/anno...sa2005-18.html
>
> Mozilla indicates version 1.01 is not vulnerable.
>
> I thought folks might be interested. I would upgrade, while I
> understand the complexity of the exploit (ie injecting code at the fail
> point when memory heap is exhausted) a failed attempt would crash the
> browser. I would prefer my browser, or anything else, don't crash. I
> wouldn't be surprised to see the bad guys crash the browser just to be
> rude to those refusing their play toys.
>
> Winged


Was doing some research on the individual (Daniel de Wildt) who surfaced
this exploit and saw he had identified several others. (Just checking to
see if he was related to Microsoft, would have made a nice conspiracy
theory), but alas he has surfaced several MS exploits too. Someone get
this guy a passport and a job, he would be useful! He is involved in
much more than researching exploits, a true nerd. Of course it sounds
like he has a very full plate. An interesting person. Great google
excursion.

Winged


winged
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Error: Physical sythesis tool PALAC is not supported by Formal Verification tool Conf bbiandov Software 0 12-22-2008 05:25 AM
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 02:11 AM
Need help on Modelsim VHDL syntax? ASAP:) kaji General Help Related Topics 0 03-14-2007 10:43 PM
Need help on a Modelsim VHDL Syntax? ASAP:) kaji Software 0 03-14-2007 10:43 PM
Need Help on a Modelsim VHDL Syntax....ASAP:) kaji Hardware 0 03-14-2007 10:41 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46