Security experts at
Packet Storm have
published
proof-of-concept
code that exploits an unpatched flaw in the
Firefox 1.5 browser,
making the application vulnerable to a denial of service attack.
The code marks the first publicly disclosed security vulnerability in Firefox
1.5 since the version became available in late November.
The published code will add a large entry to the 'history.dat' file of the
browser, causing the application to freeze or crash the next time it is
launched.
Users can fix the problem by manually erasing the file. Another option is to
change the browser setting to disable the saving of history data by setting the
days of saved history to zero or increasing the privacy control.
"Presumably, if the topic was more tightly crafted than in the
proof-of-concept code, a more malicious attack could be crafted that would
install malware on the machine with the extra step of being reinstalled after
each restart of Firefox," Bambenek wrote.
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
Your role will be working on direct market access and exchange connectivity part of the application built in C++ on a Unix platform. The team is currently just 9 people including architect and team lead, ... more >
This is a fantastic opportunity working for a leading global software house, which is part of a larger multi media company. The role is working in the core development team in central London developing a ... more >
C++, Developer, OO, Unix/NT, API, London, City, Graduate A senior core C++/ Unix developer wanting to work in the heart of the city for one of London's most successful companies is required. The successful candidate ... more >More job opportunities