Re: [Full-disclosure] Flaw in Firefox 2.0 RC2



On 10/20/06, Jure Pečar <pegasus@xxxxxxxxxxx> wrote:
On Thu, 19 Oct 2006 13:05:48 -0400
Mark A Basil <mark.basil@xxxxxxxxxxxxxxx> wrote:
On Wed, 2006-10-18 at 10:28 +1000, jm wrote:
Firefox 1.5.07 on CentOS died quite nicely too.
Mike@xxxxxxxxx wrote:
http://lcamtuf.coredump.cx/ffoxdie.html
this exploit still works with the latest Firefox 2.0 RC3
It is also affecting any browser using the Gecko rendering engine
(gecko-1.8 at least), such as Epiphany and Galeon, and not restricted to
'Firefox'.
Also renders Opera 9.02 (build 434) on linux unresponsive at 100% cpu usage.

Netcat 0.7.1 isn't affected on FreeBSD 7.0.

--
Tyop?
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Firefox v. Epiphany
    ... > replaced by Epiphany - I preferred Galeon). ... I switched to Firefox and I haven't upgraded to FC3 yet. ... It's a truly great browser. ...
    (Fedora)
  • Re: Gnome-Ersatz fuer KDE-Programme?
    ... > (argumente galeon als Gnome-App z.b. Firefox vorzuziehen). ... - bessere Bookmark-Verwaltung als Epiphany, ...
    (de.comp.os.unix.apps.gnome)
  • Transitioning to Firefox
    ... For a very long time now I've used Galeon as my browser because its ... is even more so, if it weren't for its bookmarking system), and used ... with Firefox approaching 1.0 I ... general browsing features that neither Galeon or Epiphany have, ...
    (Fedora)
  • Re: Firefox v. Epiphany
    ... On 11/20/2004 02:13:01 AM, Colin Paul Adams wrote: ... > replaced by Epiphany - I preferred Galeon). ... > Now I'm about to upgrade to FC3, should I go with Firefox instead? ...
    (Fedora)
  • Re: Firefoxquestions
    ... I think the closest thing in Firefox to the ctrl+o behaviour in Galeon ... is ctrl+l which takes you straight to your URL input at the top ... Manager' both 'Session Manager' and 'Tab Mix Plus' are returned; ...
    (Ubuntu)