iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Firefox Zero-Day DoS Discovered
Search:
[ insider_reports_insider ]

Firefox Zero-Day DoS Discovered



David Utter
Staff Writer
2006-04-25

SecurityProNews: Insider Reports Insider Reports RSS Feed


A Javascript handling issue in the latest version of the Firefox browser can be exploited to cause a buffer overflow and crash the browser.

Javascript Handling Issue Causes Crash
Javascript Handling Issue Causes Crash

Proof of concept code provided in the Milw0rm exploit advisory did cause a Firefox 1.5.0.2 browser to crash immediately. That behavior prompted both the Mozilla feedback agent and Microsoft's error reporting tool to launch and request permission to send the details of the crash along to the respective organizations.

The milw0rm alert carried a description of the problem that will likely prompt Mozilla to provide a quick update:

A handling issue exists in how Firefox handles certain Javascript in js320.dll and xpcom_core.dll
regarding iframe.contentWindow.focus(). By manipulating this feature a buffer overflow will occur.

The exploit exists in Linux as well as Windows versions of Firefox.

Mozilla recently released Firefox 1.5.0.2 on April 13th. The update provided security fixes for nineteen problems in the browser, with eleven of those rated "critical" by the organization.

Overall, Firefox has fared better than Internet Explorer, the world's most widely used browser, when it comes to security issues. As the Firefox browser grew in global market share to the ten percent range, the number of people trying to find problems with it has likewise increased.

Mozilla has been able to keep the browser updated a little more quickly than Microsoft has with IE. When a potentially dangerous IE flaw became publicly known after Microsoft issued its March security patches, a pair of third-party security companies released unofficial patches for the problem when Microsoft appeared to refuse to release a patch outside of its regular release cycle.

Microsoft did not recommend the use of those patches from eEye and Determina because of the modifications the patches would make to windows. Both companies noted that their patches could be easily uninstalled when an official patch was released.

---
Tag:

Add to | DiggThis | Yahoo! My Web | PreFound.com

Bookmark WebProNews:





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds