Re: [Full-disclosure] FireFox Host: Buffer Overflow is not just exploitable on FireFox

From: Juha-Matti Laurio (juha-matti.laurio_at_netti.fi)
Date: 09/17/05

  • Next message: none none: "[Full-disclosure] Small Linux Kernel Patch To Check For Shdr"
    Date: Sat, 17 Sep 2005 18:45:19 +0300 (EEST)
    To: full-disclosure@lists.grok.org.uk, gautam.bipin@gmail.com
    
    

    > On 9/14/05, Juha-Matti Laurio <juha-matti.laurio@netti.fi> wrote:
    > > >Hi all,
    > > >Research and development has let to a ~90% reliable working exploit
    for the
    > > >IDN Heap Buffer overrun in FireFox on WinXP and Win2k3 as long as DEP is

    A short correction that this part of message is from SkyLined's posting:
    http://lists.grok.org.uk/pipermail/full-disclosure/2005-September/037045.html
     
    - Juha-Matti

    > What? The exploit only works on winxp sp2 if DEP is turned off.....
    > (or is it JUST there is another way in?) Your explanation is
    > confusing!
    >
    > DEP That's turned ON by default... & most of us choose to turn it on
    > for all service & softwares.
    >
    > --
    >
    > Bipin Gautam
    > http://bipin.tk
    >
    > Zeroth law of security: The possibility of poking a system from lower
    > privilege is zero unless & until there is possibility of direct,
    > indirect or consequential communication between the two...

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: none none: "[Full-disclosure] Small Linux Kernel Patch To Check For Shdr"

    Relevant Pages

    • Re: Combine 2 formulas
      ... Apparently, I had made the correction in an earlier posting, but not in the template that I relied for my subsequent posting. ... > I am getting a value# error for anything in cell J10 ... adjust cents up to the next .x9 cent ending ...
      (microsoft.public.excel.misc)
    • Re: counterreaction?
      ... correcting his usage of it to refer to reform schools and ... as Peter supplied absolutely no explanation for posting the ... Wikipedia...well, patronising, really. ... find the posting of the link either patronising or insulting. ...
      (alt.usage.english)
    • Re: Cant find right thread -- got my MODES answer
      ... asserting that someone is wrong and telling them to ... DM> explanation, but you might have the idea that that's what ... resistant to correction. ... cwilbur at chromatico dot net ...
      (rec.music.theory)
    • Re: SP Addition: ancestry of Elizabeth de Caldcotis (and Livingston of Kilsyth)
      ... If you discover that you have made a typographical error in a posting, you tend to make another nearly identical posting with the error corrected; your subject for the new posting may even say "". ... Since the posting with the error will be in the archives of GEN-MEDIEVAL indefinitely, and thus retrievable in response to searches, your reposting the complete original with correctionis a defensible strategy. ... This insures that any query that retrieves the original will also retrieve the corrected version. ... For example, the correction to which I am responding could have had a new first line, ...
      (soc.genealogy.medieval)
    • Re: timezones and posting date headers
      ... That's why your headers have a time zone specified. ... And I know that my own posting clock is ... magnitude of a correction was ever greater than 90 seconds, ... based posting interface all liars. ...
      (microsoft.public.vb.general.discussion)