Firefox
Flaw in version 1.5 could be exploited to install malware
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

First Firefox 1.5 exploit made public

Popular browser vulnerable to denial of service attack

Tom Sanders in California, vnunet.com 09 Dec 2005
ADVERTISEMENT

Security experts at Packet Storm have published proof-of-concept code that exploits an unpatched flaw in the Firefox 1.5 browser, making the application vulnerable to a denial of service attack. 

The code marks the first publicly disclosed security vulnerability in Firefox 1.5 since the version became available in late November.

The published code will add a large entry to the 'history.dat' file of the browser, causing the application to freeze or crash the next time it is launched.

Users can fix the problem by manually erasing the file. Another option is to change the browser setting to disable the saving of history data by setting the days of saved history to zero or increasing the privacy control.

While the proof-of-concept code is relatively harmless, the flaw could be exploited to install malware, according to John Bambenek, a researcher with the University of Illinois at Urbana-Champaign and a volunteer at the SANS Internet Storm Center

"Presumably, if the topic was more tightly crafted than in the proof-of-concept code, a more malicious attack could be crafted that would install malware on the machine with the extra step of being reinstalled after each restart of Firefox," Bambenek wrote.

OperaRapid response to Secunia alert  25 Nov 2005
MicrosoftUK company releases proof-of-concept exploit for browser flaw  22 Nov 2005
MicrosoftSoftware maker offers Internet Explorer 7 beta to an audience of hackers  30 Sep 2005
FirefoxBuffer overflow flaw affects all versions of the open source browser  12 Sep 2005
Next public version scheduled for September  25 Jul 2005
Version 1.0.5 designed to be more stable  13 Jul 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Foster Wheeler
Analyst Programmer - Applix TM1 -Competitive Salary - ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals ... more >
| Foster Wheeler
Analyst Programmer - JDEdwards- ReadingFoster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil amp; LNG, refining, petrochemicals lt;/p> Our UK-headquartered operations ... more >
| Google
The area: DoubleClick DoubleClick, a Google company, enables top marketers, publishers and agencies to utilize DoubleClick's expertise in ad serving, rich media, video and affiliate marketing to help them make the most of the digital ... more >
| Google
The area: Engineering Management Google's engineering teams exhibit high energy, deep technical skills and a drive to get things done. Our Engineering Managers need to be technical leaders and motivators who are comfortable leading these ... more >
More job opportunities