0DAY Firefox Remote Code Execution and Denial of Service Vulnerability <=1.5.0.2 iframe.contentWindow.focus()
- From: chris@xxxxxxxxxxx
- Date: 24 Apr 2006 01:35:06 -0000
---------------------------------------------------
Software:
Firefox Web Browser
Tested:
Linux, Windows clients' version 1.5.0.2
Result:
Firefox Remote Code Execution and Denial of Service
Problem:
A handling issue exists in how Firefox handles certain Javascript in js310.dll and xpcom_core.dll
regarding iframe.contentWindow.focus(). By manipulating this feature a buffer overflow will occur.
Proof of Concept:
http://www.securident.com/vuln/ff.txt
Credits:
splices(splices [dot] org)
spiffomatic64(spiffomatic64 [dot] com)
Securident Technologies (securident [dot] com)
------------------------------------------------
- Prev by Date: Re: Delphi and buffer overflows
- Next by Date: Possible Overflow in MS Word 2003
- Previous by thread: IE Update Possible vulnerability
- Next by thread: Possible Overflow in MS Word 2003
- Index(es):
Relevant Pages
|
|