Jump to content

Firefox 3.5.1 Crashed By A Simple JavaScript


bochiman
 Share

Recommended Posts

It could be hard to believe, but after the recent release of Firefox 3.5.1 update, a new security flaw that allows remote code execution through JavaScript code was discovered. A proof of concept for the exploit code was also made public and it works, because Mozilla Firefox browser is still vulnerable to a stack-based buffer overflow. The attacker could generate the buffer overflow by sending long Unicode strings to the document.write method and in this way is possible the remote code execution to compromise an operating system or a DOS (Denial Of Service) attack.

Read More

Link to comment
Share on other sites

True. And when IE gets released with security vulnerabilities like this one, everyone has to know about it... Firefox is a hippy compared to its whiney girl rival, Internet Exploder.

A note about this warning though; apparently it also counts for Flock users too. Not just Firefox users. Flock is still based on Firefox and has the same updates, only thing is Flock's updates are a little different.

I don't know where I found the link to this but I'll post it once I've found it.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy