Forum Moderators: open

Message Too Old, No Replies

New Firefox Vulnerability

Mozilla Firefox JavaScript Engine Hole

         

outrun

4:44 am on Apr 5, 2005 (gmt 0)

10+ Year Member



[secunia.com...]


The vulnerability is caused due to an error in the JavaScript engine, as a "lambda" replace exposes arbitrary amounts of heap memory after the end of a JavaScript string.

Successful exploitation may disclose sensitive information in memory.

Heard this before?
Solution: Disable Javascript

<added>Mozilla Suite has the same Problem
[secunia.com...]
</added>

tedster

6:12 am on Apr 5, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks, outrun. Looks like version 1.0.3 will soon be with us.