iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Firefox Fixing DoS Flaw Soon
Search:
[ insider_reports_insider ]

Firefox Fixing DoS Flaw Soon



David Utter
Staff Writer
2006-04-28

SecurityProNews: Insider Reports Insider Reports RSS Feed


Another incremental release of the Firefox browser should be available online today in response to a zero-day exploit that became public earlier in the week.

The Time Approaches for Firefox DoS Fix
The Time Approaches for Firefox DoS Fix

The Mozilla Foundation announced another update to the latest version of the Firefox browser will be forthcoming. The update arrives in response to a Javascript handling issue in version 1.5.0.2 of the browser.

"We are going to ship a smaller 1.8.0.3/1.5.0.3 release in order to quickly respond to a publicly reported security issue (bug 334515)," said the entry at Mozilla Wiki about the patch.

The exploit being addressed can cause a Firefox browser to crash immediately upon execution. A Javascript handling issue regarding iframe.contentWindow.focus() can be manipulated into a buffer overflow.

That causes Firefox to crash immediately. A proof of concept link in the Milw0rm list posting on the flaw placed an iframe in the Firefox window, then the code forced the DoS condition as described.

Since the flaw exploits Javascript, it is not limited to the Windows platform. Firefox running on Linux can be exploited in the same way.

The Secunia advisory website rated the problem 'not critical' since the contentWindow.focus() call only shuts down Firefox. It does not enable remote code execution or other threats.

---
Tag:

Add to | DiggThis | Yahoo! My Web | PreFound.com

Get all the updates in RSS:





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds