Firefox 3.5.1 Crashed By A Simple JavaScript

firefox-logo1It could be hard to believe, but after the recent release of Firefox 3.5.1 update, a new security flaw that allows remote code execution through JavaScript code was discovered. A proof of concept for the exploit code was also made public and it works, because Mozilla Firefox browser is still vulnerable to a stack-based buffer overflow. The attacker could generate the buffer overflow by sending long Unicode strings to the document.write method and in this way is possible the remote code execution to compromise an operating system or a DOS (Denial Of Service) attack.

Mozilla has responded to the press articles regarding the existence of the stack-based buffer overflow security flaw in Firefox 3.5.1 and previous versions, by explaining the fact that this browser security leak is not exploitable:

“These strings can result in crashes of some versions of Firefox. On Windows, Firefox 3.0.x and Firefox 3.5.x are terminated due to an uncaught exception during an attempt to allocate a very large string buffer; this termination is safe and immediate, and does not permit the execution of attacker code.“

Several security websites has confirmed the new Firefox security flaw, like SANS Internet Storm Center and IBM ISS X-Force. The proof of concept for the JavaScript exploit code shows a simple function that is capable to crash Firefox 3.5.1 browser and maybe with a few tweaks the code could be optimized for successful remote code execution.

Until now, a patch is not available for this security issue discovered in Firefox 3.5.1. You should also know that even JavaScript is disabled, an attacker is still able to execute remote code through the web browser (by XSS for example) in order to gain the total control of your operating system. Therefore, there is recommended to use only safe web sites and a daily updated anti-virus software.

http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/digg_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/reddit_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/dzone_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/stumbleupon_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/delicious_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/blinklist_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/furl_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/newsvine_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/technorati_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/magnolia_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/google_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/facebook_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/yahoobuzz_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/sphinn_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/mixx_48.png http://www.downloadtube.com/blog/wp-content/plugins/sociofluid/images/twitter_48.png
Tags: , , , , , ,

Related Articles

2 Responses to “Firefox 3.5.1 Crashed By A Simple JavaScript”

  1. Firefox 3.5.1 Crashed By A Simple JavaScript - Webmaster Forum Says:

    [...] Firefox 3.5.1 Crashed By A Simple JavaScript It could be hard to believe, but after the recent release of Firefox 3.5.1 update, a new security flaw that allows remote code execution through JavaScript code was discovered. A proof of concept for the exploit code was also made public and it works, because Mozilla Firefox browser is still vulnerable to a stack-based buffer overflow. The attacker could generate the buffer overflow by sending long Unicode strings to the document.write method and in this way is possible the remote code execution to compromise an operating system or a DOS (Denial Of Service) attack. Read Entire Article [...]

  2. Firefox 3.7 Will Look Better On Windows 7 And Vista | Internet News | Free Download Windows Software Says:

    [...] Regarding Firefox browser, in the last days, you might have heard in the news only about the security flaws that affect even [...]

Leave a Reply