Firefox
Flaw in version 1.5 could be exploited to install malware
R E L A T E D   C O N T E N T
ADVERTISEMENT

First Firefox 1.5 exploit made public

Popular browser vulnerable to denial of service attack

Tom Sanders in California, vnunet.com 09 Dec 2005
ADVERTISEMENT

Security experts at Packet Storm have published proof-of-concept code that exploits an unpatched flaw in the Firefox 1.5 browser, making the application vulnerable to a denial of service attack. 

The code marks the first publicly disclosed security vulnerability in Firefox 1.5 since the version became available in late November.

The published code will add a large entry to the 'history.dat' file of the browser, causing the application to freeze or crash the next time it is launched.

Users can fix the problem by manually erasing the file. Another option is to change the browser setting to disable the saving of history data by setting the days of saved history to zero or increasing the privacy control.

While the proof-of-concept code is relatively harmless, the flaw could be exploited to install malware, according to John Bambenek, a researcher with the University of Illinois at Urbana-Champaign and a volunteer at the SANS Internet Storm Center

"Presumably, if the topic was more tightly crafted than in the proof-of-concept code, a more malicious attack could be crafted that would install malware on the machine with the extra step of being reinstalled after each restart of Firefox," Bambenek wrote.

OperaRapid response to Secunia alert  25 Nov 2005
MicrosoftUK company releases proof-of-concept exploit for browser flaw  22 Nov 2005
MicrosoftSoftware maker offers Internet Explorer 7 beta to an audience of hackers  30 Sep 2005
FirefoxBuffer overflow flaw affects all versions of the open source browser  12 Sep 2005
Next public version scheduled for September  25 Jul 2005
Version 1.0.5 designed to be more stable  13 Jul 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Aston Carter
Your role will be working on direct market access and exchange connectivity part of the application built in C++ on a Unix platform. The team is currently just 9 people including architect and team lead, ... more >
| Aston Carter
This is a fantastic opportunity working for a leading global software house, which is part of a larger multi media company. The role is working in the core development team in central London developing a ... more >
| Aston Carter
C++, Developer, OO, Unix/NT, API, London, City, Graduate A senior core C++/ Unix developer wanting to work in the heart of the city for one of London's most successful companies is required. The successful candidate ... more >
More job opportunities