oops ... FF in trouble from zero-day flaw also

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,751
Reaction score
1,210
...
happywave.gif


Quick update ... well I do take my posts seriously in this forum. ;)

http://developer.mozilla.org/devnew...e-possible-vulnerability-reported-at-toorcon/

We got a chance to talk to Mischa Spiegelmock, the Toorcon speaker that reported the potential javascript security issue referenced earlier. He gave us more code to work with and also made this statement and agreed to let me post it here:

The main purpose of our talk was to be humorous.

As part of our talk we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this, and I personally have not gotten it to result in code execution, nor do I know of anyone who has.

I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven’t used it to take over anyone else’s computer and execute arbitrary code.

I do not have 30 undisclosed Firefox vulnerabilities, nor did I ever make this claim. I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not.

I apologize to everyone involved, and I hope I have made everything as clear as possible.

Sincerely,

Mischa Spiegelmock

Even though Mischa hasn’t been able to achieve code execution, we still take this issue seriously. We will continue to investigate.

-Window Snyder
... still, "No Script" is a good extention that does what it says on the tin ... worth an install anyway.



user.gif

 
Nothing is truly safe I suppose :) The problem is the little blighters who exploit these holes :user:

I'll download that extension now if it's useful :D :thumb:
 
I knew it was too good to be true all along...Nothing is truly safe 100%...;)
 
happywave.gif
Ermm how do you get rid of the annoying info bar at the bottom of the screen after you have downloaded this software .
bowdown.gif
 
Back
Top