Security

New vulnerability discovered for Firefox 3.5.1 (Update)

by Steve Ragan - Jul 18 2009, 18:30

Share


Share

Interested in a more interactive TTH? Join our Facebook Group
Want regular updates from The Tech Herald? Follow us on Twitter

Comment on this Story

Note our older Talkback system is still running below. We hope to import existing comments into the new system shortly. Guest posting is still allowed, however, you can now login with any number of social network accounts.

Talkback

Add your comment (no registration required)

page: 1 

Giorgio MaoneJul 18th, 2009 - 19:09:20

This 'eEye' is utterly ignorant.
NoScript features the first and best client side anti-XSS protection, therefore it's practically impossible running JavaScript code 'from an untrusted website without the consent of the user'.

Report this comment

B0risJul 19th, 2009 - 18:00:08

Uh, eEye are well-recognised, successful security researchers, responsible for finding several notable vulnerabilities including the one used by Code Red worm. You must be feeling very cocky today to call them 'completely ignorant'!
Someone is certainly ignorant... Of course NoScript won't protect you from *a compromised site on your whitelist*. If a site is on your whitelist, then by your own choice NoScript won't protect you from it.

Report this comment

nemoJul 19th, 2009 - 18:47:41

Apparently this crashes pretty much every browser out there (Chromium, Safari, Firefox) and is just a null pointer exception.

To the reporter who posted this, are you sure this is exploitable with remote code execution?

Because crashing a browser using javascript, while annoying, is not exactly uncommon. Solution for user. Don't go to the bastardly site (and maybe use NoScript).

Report this comment

jasonJul 19th, 2009 - 18:52:46

Usually bad code comes from a different domain. Because there is no reason to load a script from yourbank.com.jijshu965543.cn when you are browsing yourbank.com

Report this comment

Asa DotzlerJul 19th, 2009 - 19:21:34

This is a browser out of memory crash. There is no evidence that this is exploitable while all evidence points to it not being exploitable. Pretty much all browsers crash from this but that doesn’t mean that it’s a security issue.

Report this comment

Mike ShaverJul 19th, 2009 - 22:37:17

This is incorrect. It is neither a stack overflow nor exploitable. Please see the Mozilla Security Blog for more details. (I can't post a link to it here because it is rejected by the comment system, alas.)

Report this comment

MikeJul 21st, 2009 - 21:00:06

It doesn't seem to crash IE8 on my machine. It freeze it for about 10 seconds, But it continue to work fine without crashing.

Report this comment

page: 1 

Add your comment (no registration required)

AddThis Social Bookmark Button

Advertising

Advertising

Advertising

Latest

Motorola launches Android-equipped CLIQ through T-Mobile
AT&T sues Verizon over map commercials
The Pirate Bay effect causes piracy related sites to surge
Facebook password scam circulates online
M86 Security snatches up Finjan in undisclosed deal

Latest Articles on Monsters&Critics

Quake shakes southern Iranian port, 700 injured (Roundup)
Saudi soldier killed, 11 injured in clashes with gunmen near border
Brewer Carlsberg posts 329m dollar third-quarter profits
Energy giant Statoil's third-quarter net income up 6 per cent
Hundreds of Philippine police join search for abducted Irish priest
Five British soldiers killed in southern Afghanistan (1st Lead)
Israel Navy intercepts weapons-laden cargo ship off Israeli coast
Toyota quits Formula One (1st Lead)
US envoy meets Myanmar pro-democracy icon Aung San Suu Kyi (1st Lead)
Hong Kong toasts success as wine imports surge 40 per cent

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173

Notice: Undefined index: continent in /home/thetechh/public_html/class/class.slot.php on line 173