Unpatched Firefox 1.5 Exploit Made Public 309
ThatGuyGreg writes "C|Net is reporting that an unpatched exploit in Firefox 1.5 has been made public, making it very easy for ne'er-do-well-sites to cause your browser to crash on startup with a single visit. Until a patch is released, it is recommended that you disable your history.dat file."
The fix (Score:5, Informative)
Only crashes? (Score:5, Informative)
Incremental updates (Score:3, Informative)
Stopping the stupidity (Score:5, Informative)
Cheers,
Toby Haynes
Um... Did you RTFA? It's not an exploit (Score:5, Informative)
Quote from the bottom of the article:
Correction: This story incorrectly stated the affiliation of Mike Schroepfer, Mozilla's results in verifying the Firefox 1.5 flaw, and the nature of the problem. Schroepfer is vice president of engineering with Mozilla Corp., and Mozilla has not been able to verify its browser can crash and lead to a denial-of-service condition. The problem itself was a not security vulnerability but actually a flaw in the browser.
Read the article before you consider posting it with a sensational title!
Someone needed to create a scoop. (Score:4, Informative)
Wow, that is accurate reporting, which was then amplified in the summary to the point of absurdity.
Re:FC4, 1.5 (Score:5, Informative)
Mozilla Foundation, which released Firefox, said it was not able to confirm the browser would crash or be at risk of a DOS attack, after visiting certain Web sites.
"We have gotten no independent verification that it crashes (Firefox), but there have been a lot of attempts to try," Schroepfer said.
Apparently they're having a hard time duplicating this particular bug. Has anyone here on
Re:Obligatory Jamaican Response (Score:5, Informative)
Firefox history code is horrible (Score:2, Informative)
so... (Score:5, Informative)
Patched. I use the history feature about twice a year, won't miss it till the right fix is found.
Not quite like disabling all the javascript in MSIE, is it?
Re:Stopping the stupidity (Score:3, Informative)
Re:Is that a Product plug I see? (Score:3, Informative)
This bug is slightly lame, even as DOS -- There are no confirmed reports from half-or-more-brain-having people that it even crashes the browser in the first place. All it does is make the subsequent startups slow, especially noticable in slower machines.
See bug 319004 at bugzilla.mozilla.org.
Posting from an "Exploited" FF 1.5 (Score:5, Informative)
False alarm. No security-related concerns, just overenthusiastic reporting.
If you run the script below, it will create a page with a title that's quite huge. Close your browser and open it again. The browser will spin for about 2 minutes what it tries to make sense the contents of your history file. Once it's finished, you'll be back up and running, with no degradation in performance or visible side-effects. You'll be able to even view your browsing history (including the offending page). In fact, I'm posting this response after following the process described above (on WinXP), and I have a history entry entitled "AAAAAAAAAAAAAAAAA..."
A bit of an annoyance, but hardly a security issue.
Here's the official exploit code:
Non-Story (Score:5, Informative)
"Correction: This story incorrectly stated the affiliation of Mike Schroepfer, Mozilla's results in verifying the Firefox 1.5 flaw, and the nature of the problem. Schroepfer is vice president of engineering with Mozilla Corp., and Mozilla has not been able to verify its browser can crash and lead to a denial-of-service condition. The problem itself was not a security vulnerability but actually a flaw in the browser."
So Firefox crashes, but no security vunerabilty.
Re:FC4, 1.5 (Score:4, Informative)
As other have posted, it crashes IE as well. And every firefox crash I've had since I've installed 1.5 appears to have been QuickTime related!!!
All happening after installing 7 except for one.
Re:IE's execution of arbitrary code (Score:3, Informative)
It was fixed 24 hours after full disclosure, and only Win32 versions of Mozilla were vulnerable, doesn't this ring a bell?
Anyway, read this link [newsforge.com] for more info.