There is a new advisory out that indicates there is a remote denial of service exploit in Firefox 1.5.0.7 and Firefox 2. The original post indicated that there could be a buffer overflow and remote code execution component, but as of 10/31 this has not been verified. This exploit will occur when a specifically crafted webpage tries to create a range object with "createRange". So far it will only make the browser crash. If new information is made available, we will post updates.
--- John Bambenek bambenek /at/ gmail (dot) com |
John 262 Posts ISC Handler Nov 1st 2006 |
Thread locked Subscribe |
Nov 1st 2006 1 decade ago |
Sign Up for Free or Log In to start participating in the conversation!