Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Unpatched Firefox 1.5 exploit made public
Cnet ^ | 12/08/2005 | Dawn Kawamoto

Posted on 12/08/2005 4:06:06 PM PST by zeugma

Exploit code for the latest version of open-source browser Firefox was published Wednesday, potentially putting users at risk of a denial-of-service attack.

The exploit code takes advantage of a bug in the recently released Firefox 1.5, running on Windows XP with Service Pack 2. Firefox, which initially debuted over a year ago, has moved swiftly to capture 8 percent of the browser market.

The latest Firefox flaw exists in the history.dat file, which stores information from Web sites users have visited with the Firefox 1.5 browser, according to a posting on the Internet Storm Center, which monitors online threats.

"If the topic of a page is crafted to be long enough, it will crash the browser each time it is started after going to such a page," according to the Internet Storm Center posting. "Once this happens, Firefox will be unable to be started until you erase the history.dat file manually."

In testing Firefox 1.5 without a system running McAfee security software, the Firefox 1.5 browser would stall and not respond to a user's mouse, said Johannes Ullrich, chief research officer for the Sans Institute, which runs the Internet Storm Center.

"Users have to kill out of the browser and start over again. This stalled browser creates a DOS (denial of service) condition," Ullrich said.

Packet Storm, the security group that initially published the proof-of-concept exploit code, noted that in addition to the potential denial-of-service attack that could follow a buffer overflow, systems may also be subject to a malicious execution of code.

Ullrich, however, said while the potential may exist, it has not been proven either way that malicious code could be executed.

Mozilla Foundation, which released Firefox, said it was not able to confirm the browser would crash or be at risk of a DOS attack, after visiting certain Web sites. And Mozilla has not received any reports from users of such a problem, said Mike Schroepfer, vice president of engineering for Mozilla Corp.

He added that Firefox 1.5 can be slugglish on its next start-up, due to a bug in the history.dat, but it is not a security problem.

"We have gotten no independent verification that it crashes (Firefox), but there have been a lot of attempts to try," Schroepfer said.  

Correction: This story incorrectly stated the affiliation of Mike Schroepfer, Mozilla's results in verifying the Firefox 1.5 flaw, and the nature of the problem. Schroepfer is vice president of engineering with Mozilla Corp., and Mozilla has not been able to verify its browser can crash and lead to a denial-of-service condition. The problem itself was not a security vulnerability but actually a flaw in the browser.


TOPICS: Business/Economy; Crime/Corruption; Miscellaneous; News/Current Events
KEYWORDS: browser; exploit; firefox; history
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 141-158 next last
If you're using Firefox, turn off your history to keep evil sites from being able to crash your browser.

The actual likelihood of running into one of these unless you regularly browse through the shady side of the net, but it's always bettyer to be safe than sorry. Note: that this particular defect does not propagate. That is, it is not a virus or worm. Some nasty person can make your browser crash, which can be fairly traumatic I'll admit after your browser has been up for a week or so with 30 tabs - but still.

1 posted on 12/08/2005 4:06:06 PM PST by zeugma
[ Post Reply | Private Reply | View Replies]

To: zeugma
the shady side of the net

Does that include porn sites?

2 posted on 12/08/2005 4:08:53 PM PST by FEARED MUTATION
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
If you're using Firefox, turn off your history to keep evil sites from being able to crash your browser.

Proof of concept code does not equal an exploit in the wild.

You know, it's really nice of these security companies to wait until the final release before announcing these things. Mozilla puts out nightly builds, betas, and release candidates for a reason.
3 posted on 12/08/2005 4:12:47 PM PST by Terpfen (Libby should hire Phoenix Wright.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
If you're using Firefox, turn off your history to keep evil sites from being able to crash your browser.

Is it turned off, if nothing drops down when you click on the address bar?

4 posted on 12/08/2005 4:16:10 PM PST by don-o (Don't be a Freeploader. Do the right thing. Become a Monthly Donor! '98'er)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FEARED MUTATION

"Does that include porn sites?" Why, no, of course not. Go right ahead.:)


5 posted on 12/08/2005 4:17:18 PM PST by dynachrome ("Where am I? Where am I going? Why am I in a handbasket?")
[ Post Reply | Private Reply | To 2 | View Replies]

To: zeugma

The sample exploit doesn't crash Firefox on my system with OS X 10.4.2. It does seem to make Firefox take a long time to quit and launch though.


6 posted on 12/08/2005 4:23:59 PM PST by ThinkDifferent (I am a leaf on the wind)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

Do you have any tips on running firefox from a removable drive? I haven't tried it yet but people here at work say they run it from their jump drives.


7 posted on 12/08/2005 4:24:21 PM PST by raybbr
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
How many users of Firefox 1.5 are out there?
8 posted on 12/08/2005 4:28:05 PM PST by tubebender (You can't make Chicken Salad from Chicken Bleep...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: tubebender

Count one here. :)


9 posted on 12/08/2005 4:51:15 PM PST by M_i_G
[ Post Reply | Private Reply | To 8 | View Replies]

To: tubebender

I'm one and I appreciate the posts about Firefox that appear on FR from time to time.


10 posted on 12/08/2005 4:51:51 PM PST by Malesherbes
[ Post Reply | Private Reply | To 8 | View Replies]

To: FEARED MUTATION
Does that include porn sites?

Only in a technically true sense.

11 posted on 12/08/2005 4:54:08 PM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: tubebender

Thats me, and I really like it.


12 posted on 12/08/2005 4:56:36 PM PST by MilspecRob (Most people don't act stupid, they really are.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: tubebender

One here also.


13 posted on 12/08/2005 4:59:04 PM PST by Ole Okie
[ Post Reply | Private Reply | To 8 | View Replies]

To: raybbr
Do you have any tips on running firefox from a removable drive? I haven't tried it yet but people here at work say they run it from their jump drives.

No. I haven't tried that either, but I've seriously considered checking out how well it works. Personally, I prefer Knoppix for that kind of thing. It doesn't work if you want to save bookmarks and cookies though.

14 posted on 12/08/2005 5:01:04 PM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: don-o
Is it turned off, if nothing drops down when you click on the address bar?

No. That's actually two different things, I believe. I could be wrong though. I'll have to check it out. Does anyone else know?

15 posted on 12/08/2005 5:02:11 PM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ThinkDifferent

Update: Slashdot posters are reporting similar behavior. The exploit doesn't crash Firefox, but it can make it take a long time to read the history file and thus appear to have hung. It's unlikely that this is an actual security threat, although it could be annoying.


16 posted on 12/08/2005 5:02:31 PM PST by ThinkDifferent (I am a leaf on the wind)
[ Post Reply | Private Reply | To 6 | View Replies]

To: tubebender
I'm not sure how many users there are. When version 1.5 was released, there were a million downloads during the first 24 hours, so apparently, there are a few of us out here. That doesn't count people like me who download one copy and load onto 4 computers here at home, and about 10 at work.
17 posted on 12/08/2005 5:04:03 PM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: zeugma
I prefer Knoppix for that kind of thing.

Is that from Germany, or where? Don't you have to burn a new CD every time there's a security patch? Such as if your firefox on your bootable knoppix needed this patch, you'd have to make a whole new cd wouldn't you?

18 posted on 12/08/2005 5:06:19 PM PST by Golden Eagle
[ Post Reply | Private Reply | To 14 | View Replies]

To: ThinkDifferent
Update: Slashdot posters are reporting similar behavior. The exploit doesn't crash Firefox, but it can make it take a long time to read the history file and thus appear to have hung. It's unlikely that this is an actual security threat, although it could be annoying.

Good to know. I would imagine in that case, that a quick fix if you got bitten by this would be to simply clear your history.

I figure it's better safe than sorry with this type of thing. Better to post, then clarify as more information is forthcoming.

19 posted on 12/08/2005 5:06:49 PM PST by zeugma (Warning: Self-referential object does not reference itself.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: tubebender

me three


20 posted on 12/08/2005 5:06:58 PM PST by steveo (Merry Christmas everybody!)
[ Post Reply | Private Reply | To 8 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 141-158 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson