Security experts at
Packet Storm have
published
proof-of-concept
code that exploits an unpatched flaw in the
Firefox 1.5 browser,
making the application vulnerable to a denial of service attack.
The code marks the first publicly disclosed security vulnerability in Firefox
1.5 since the version became available in late November.
The published code will add a large entry to the 'history.dat' file of the
browser, causing the application to freeze or crash the next time it is
launched.
Users can fix the problem by manually erasing the file. Another option is to
change the browser setting to disable the saving of history data by setting the
days of saved history to zero or increasing the privacy control.
"Presumably, if the topic was more tightly crafted than in the
proof-of-concept code, a more malicious attack could be crafted that would
install malware on the machine with the extra step of being reinstalled after
each restart of Firefox," Bambenek wrote.
Analyst Programmer - Applix TM1 -Competitive Salary - ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals ... more >
Analyst Programmer - JDEdwards- ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals lt;/p> Our UK-headquartered operations ... more >
The area: DoubleClick DoubleClick, a Google company, enables top marketers, publishers and agencies to utilize DoubleClick's expertise in ad serving, rich media, video and affiliate marketing to help them make the most of the digital ... more >
The area: Engineering Management Google's engineering teams exhibit high energy, deep technical skills and a drive to get things done. Our Engineering Managers need to be technical leaders and motivators who are comfortable leading these ... more >More job opportunities