nsane.forums Posted July 14, 2009 Share Posted July 14, 2009 The exploit portal Milw0rm has published an exploit for Firefox 3.5. The exploit demonstrates a security vulnerability by starting the Windows calculator. In testing by heise Security, the exploit crashed Firefox under Vista, but security service providers Secunia and VUPEN confirmed that attackers using prepared websites can infect PCs. The cause of the problem is a buffer overflow when processing specially prepared Font tags.The Mozilla Foundation has been informed about the problem, but so far has not responded to queries by heise Security. An update does not currently exist. So far there are no reports of sites on the internet being first to use the hole for active infections and exploitation of Windows PCs. Since the published exploit uses PC heap spraying under JavaScript, disabling JavaScript should act as a stop gap. When the exploit was tested with Windows 7 RC1, after a short time, the browser displayed a dialogue offering to abort the script. View: Original Article Link to comment Share on other sites More sharing options...
Bizarre™ Posted July 15, 2009 Share Posted July 15, 2009 I think one should be fine if they have NoScript installed :lol: Link to comment Share on other sites More sharing options...
Administrator Lite Posted July 15, 2009 Administrator Share Posted July 15, 2009 Mozilla has acknowledged that there is a critical JavaScript vulnerability in its Firefox 3.5 web browser and that it's currently working on an update to address the problem View: Original Article Link to comment Share on other sites More sharing options...
LoKz Posted July 16, 2009 Share Posted July 16, 2009 Mozilla has acknowledged that there is a critical JavaScript vulnerability in its Firefox 3.5 web browser and that it's currently working on an update to address the problem View: Original ArticleThank you for the news Lite... :) Google Chrome looks good.... :ph34r: Link to comment Share on other sites More sharing options...
donizme Posted July 16, 2009 Share Posted July 16, 2009 Even when Firefox has a vulnerability, nobody bothers to exploit it. I can't remember the last time Firefoix was being widely exploited. I can though for IE (quite a few), and I can remember something about Chrome, but not sure... ;) Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.