VinDSL writes:An exploit for the just-patched IDN bug in Mozilla's Firefox browser and namesake suite has been published on the Internet, a French security vendor said late Thursday. The hack creates a heap buffer overflow, and when it works, can give the user complete control of a vulnerable machine running Firefox, Mozilla, or even Netscape.
FrSIRT warned users of Firefox and Mozilla that the exploit code -- which FrSIRT published in its entirety, a not-uncommon practice for the firm -- should be considered a critical risk.
Tuesday, Mozilla patched the Firefox browser against the bug in its support of international domain names (IDN). Thursday, it followed up with a similar fix for the Mozilla suite in its Windows, Linux, and Mac OS X incarnations. Netscape, however, has not yet patched that browser.
Firefox 1.0.7 and Mozilla 1.7.12, which stymie the exploit, can be downloaded from the Mozilla site.
Source: informationweek.com/story/showArticle...
Firefox Exploit Ventures Into The Wild
Posted on Saturday, September 24, 2005 @ 05:38:13 CDT in Security
|
PHP-Nuke 7.9 in hand and Dangerous
Posted on Thursday, September 15, 2005 @ 17:13:59 CDT in Security
|
WARNING!!!!!! PHP-Nuke package used to highjack userinfo
Posted on Sunday, August 21, 2005 @ 01:06:52 CDT in Security
|
PHP-Nuke 7.8 RC8 OP ES
Posted on Friday, August 19, 2005 @ 12:24:55 CDT in Security bcmx55 writes:
|
Serious Security Vulnerability In Manuals - Part II
Posted on Sunday, August 14, 2005 @ 01:14:20 CDT in Security
|
Serious Security Vulnerability in Manuals
Posted on Friday, August 12, 2005 @ 14:58:08 CDT in Security
|