Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Unpatched Firefox 1.5 exploit made public
Cnet ^ | 12/08/2005 | Dawn Kawamoto

Posted on 12/08/2005 4:06:06 PM PST by zeugma

Exploit code for the latest version of open-source browser Firefox was published Wednesday, potentially putting users at risk of a denial-of-service attack.

The exploit code takes advantage of a bug in the recently released Firefox 1.5, running on Windows XP with Service Pack 2. Firefox, which initially debuted over a year ago, has moved swiftly to capture 8 percent of the browser market.

The latest Firefox flaw exists in the history.dat file, which stores information from Web sites users have visited with the Firefox 1.5 browser, according to a posting on the Internet Storm Center, which monitors online threats.

"If the topic of a page is crafted to be long enough, it will crash the browser each time it is started after going to such a page," according to the Internet Storm Center posting. "Once this happens, Firefox will be unable to be started until you erase the history.dat file manually."

In testing Firefox 1.5 without a system running McAfee security software, the Firefox 1.5 browser would stall and not respond to a user's mouse, said Johannes Ullrich, chief research officer for the Sans Institute, which runs the Internet Storm Center.

"Users have to kill out of the browser and start over again. This stalled browser creates a DOS (denial of service) condition," Ullrich said.

Packet Storm, the security group that initially published the proof-of-concept exploit code, noted that in addition to the potential denial-of-service attack that could follow a buffer overflow, systems may also be subject to a malicious execution of code.

Ullrich, however, said while the potential may exist, it has not been proven either way that malicious code could be executed.

Mozilla Foundation, which released Firefox, said it was not able to confirm the browser would crash or be at risk of a DOS attack, after visiting certain Web sites. And Mozilla has not received any reports from users of such a problem, said Mike Schroepfer, vice president of engineering for Mozilla Corp.

He added that Firefox 1.5 can be slugglish on its next start-up, due to a bug in the history.dat, but it is not a security problem.

"We have gotten no independent verification that it crashes (Firefox), but there have been a lot of attempts to try," Schroepfer said.  

Correction: This story incorrectly stated the affiliation of Mike Schroepfer, Mozilla's results in verifying the Firefox 1.5 flaw, and the nature of the problem. Schroepfer is vice president of engineering with Mozilla Corp., and Mozilla has not been able to verify its browser can crash and lead to a denial-of-service condition. The problem itself was not a security vulnerability but actually a flaw in the browser.


TOPICS: Business/Economy; Crime/Corruption; Miscellaneous; News/Current Events
KEYWORDS: browser; exploit; firefox; history
Navigation: use the links below to view more comments.
first previous 1-20 ... 81-100101-120121-140141-158 last
To: Golden Eagle

Haha! Your software purchases still fund the Dems. Can't get around that one. Amounts really don't matter...you're still helping those who oppose us, all while pointing the finger at virtually everyone else.

You know, I donate to Republican causes, but don't water it down by giving cash to the Dems with the other hand. Apparently, you support that two-faced kind of behavior, even hold it up as the ideal. That's why you're working so hard now to defend it. And, that's why I don't give my money to software companies that do it. Too bad for you that you can't say the same.


141 posted on 12/15/2005 6:52:37 PM PST by FLAMING DEATH (And now, for something completely different: www.donaldlancow.com)
[ Post Reply | Private Reply | To 137 | View Replies]

To: Tarpon
I just put a freeper folder on the desktop. When I want to follow a thread, I just drag the bookmark off the url address display and drop it in the folder. I don't like any old stuff hanging in Firefox, or any browser's memory. Firefox makes it convenient because you can set the params to delete on exit.

I am using Portable Firefox. It's on my jump drive which precludes me from dropping the url's into a folder since I am using it at work on the company's computer. They let us browse the web but won't let us install Firefox. We have to use IE. Firefox is so much more versatile and user friendly I don't understand why everyone doesn't use it.

142 posted on 12/15/2005 6:56:48 PM PST by raybbr
[ Post Reply | Private Reply | To 83 | View Replies]

To: Golden Eagle

Haha! You crack me up...trying now to turn the discussion to my socioeconomic status rather than defend your hypocrisy!

Keep digging that hole, Buzzy!


143 posted on 12/15/2005 6:56:57 PM PST by FLAMING DEATH (And now, for something completely different: www.donaldlancow.com)
[ Post Reply | Private Reply | To 140 | View Replies]

To: FLAMING DEATH

Hey it's better than outright supporting free software for communist governments. There's just no way in hell you can defend yourself on that, especially when you're so fanatical about it. One of the ten most important things in your life? Did you really post that?


144 posted on 12/15/2005 7:11:38 PM PST by Golden Eagle
[ Post Reply | Private Reply | To 141 | View Replies]

To: Golden Eagle

Fanatical? Now you're making up stuff out of thin air. Have to do that instead of facing the fact that you support the Dems and the Commies and the Planned Parenthood crowd with your own money. And I don't. I'd be looking for something else to talk about too if I were you.

I know the truth hurts, but you'll have to face it sooner or later. See ya tomorrow, Buzzy!


145 posted on 12/15/2005 7:18:37 PM PST by FLAMING DEATH (And now, for something completely different: www.donaldlancow.com)
[ Post Reply | Private Reply | To 144 | View Replies]

To: FLAMING DEATH

Don't forget to read the GNU Manifesto before you go to bed, like normal.


146 posted on 12/15/2005 7:23:33 PM PST by Golden Eagle
[ Post Reply | Private Reply | To 145 | View Replies]

To: Golden Eagle

LOL, you can't even read, you poor thing...my profile page lists "stuff I like, no matter what you think". It's not a top 10, it's just 10 things. Of course, now that you're grasping at straws, you'll look for anything. Poor baby.

Except #1. That one is my favorite.


147 posted on 12/15/2005 7:23:43 PM PST by FLAMING DEATH (And now, for something completely different: www.donaldlancow.com)
[ Post Reply | Private Reply | To 144 | View Replies]

To: Golden Eagle

I'll sleep well, knowing I didn't help the Dems in the last election!

Night, Buzzy!


148 posted on 12/15/2005 7:25:47 PM PST by FLAMING DEATH (And now, for something completely different: www.donaldlancow.com)
[ Post Reply | Private Reply | To 146 | View Replies]

To: FLAMING DEATH
Sweet Dreams, Comrade.


149 posted on 12/15/2005 7:37:41 PM PST by Golden Eagle
[ Post Reply | Private Reply | To 148 | View Replies]

To: Golden Eagle

It's a crying shame that this has become the crux of your argument, but I guess that was inevitable.


150 posted on 12/16/2005 4:51:13 AM PST by FLAMING DEATH (And now, for something completely different: www.donaldlancow.com)
[ Post Reply | Private Reply | To 149 | View Replies]

To: raybbr
I am using Portable Firefox. It's on my jump drive which precludes me from dropping the url's into a folder since I am using it at work on the company's computer.

Well just put the folder on the usb drive ... :-) I use folders for temporary bookmarks on threads and comments more and more. Doesn't clutter up the browser's bookmarks. I also find the history file not 'fine grained' enough to track back to posts I did.

These usb drives, all sorts -- flash or hard drives, are real handy gadgets. I am using them more and more. When coupled with small appliance servers, like the Linksys NSLU2 they really are handy.

151 posted on 12/16/2005 4:51:21 AM PST by Tarpon
[ Post Reply | Private Reply | To 142 | View Replies]

To: FLAMING DEATH
Well since you can't seem to mutter any response to the links I keep posting, I thought maybe you might understand some pictures.


152 posted on 12/16/2005 5:06:20 AM PST by Golden Eagle
[ Post Reply | Private Reply | To 150 | View Replies]

To: tubebender

User


153 posted on 12/16/2005 5:27:33 AM PST by Vinnie
[ Post Reply | Private Reply | To 8 | View Replies]

To: Golden Eagle

Weak.


154 posted on 12/16/2005 6:44:33 AM PST by FLAMING DEATH (And now, for something completely different: www.donaldlancow.com)
[ Post Reply | Private Reply | To 152 | View Replies]

To: FLAMING DEATH

But on your level.


155 posted on 12/16/2005 9:45:03 AM PST by Golden Eagle
[ Post Reply | Private Reply | To 154 | View Replies]

To: tubebender

Hardly use IE anymore since FFox1.0 and now 1.5 .


156 posted on 02/23/2006 9:47:43 PM PST by Westlander (Unleash the Neutron Bomb)
[ Post Reply | Private Reply | To 8 | View Replies]

To: zeugma
Its NOT an issue. It happens only on a system where you are not running a firewall or anti-virus software. If you have complete protection, Firefox is a great little browser.

(Denny Crane: "I Don't Want To Socialize With A Pinko Liberal Democrat Commie. Say What You Like About Republicans. We Stick To Our Convictions. Even When We Know We're Dead Wrong.")

157 posted on 02/23/2006 9:50:50 PM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 1 | View Replies]

To: goldstategop

Ya. firefox rocks. It's what I use 99% of the time. This is an old issue anyway.


158 posted on 02/24/2006 8:03:06 AM PST by zeugma (This post made with the 'Xinha Here!' Firefox plugin.)
[ Post Reply | Private Reply | To 157 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 81-100101-120121-140141-158 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson