Found a new high critical vulnerability in Firefox 3.0.3


Recommended Posts

http://www.milw0rm.com/exploits/6614

Severity: High

Description:

The Mozilla Firefox 3.0.3 is vulnerable to user interface event dispatcher null pointer dereference denial of service attacks. The dispatched event created dynamically leads to firefox crash when it is called directly or in a defined loop with number of generated user interface events

Proof of Concept:

http://www.secniche.org/moz303/poc.html

Mozilla 3.0.3 Crashes with unhandled exception in User Interface Dispatcher Events. If an user try to restore a session it still gives a crash.

Edited by franzon
Link to comment
Share on other sites

So theres going to be firefox 3.0.4 already for this or you reckon they'll do something like 3.0.31 now or something similar?

Knowing Mozilla, they will probably skip the thousandths, and move on to the next hundredth build. (3.0.4)

@OP: Thanks for the update. I was curious why the hell Firefox kept crashing every once in a while (when doing complicated browsing) after updating to 3.0.3... Hopefully they will fix this soon. :cry:

Link to comment
Share on other sites

Mine stays around 200k for 7 odd hours

I think you mean 200000k or 200M. That's a pathetically huge amount of ram for a bloody web browser.

Link to comment
Share on other sites

it is not the end of the world

"why so serious" you take it guys :p

Who is taking it serious, it is only a Browser. :) I don't have a memory problem with it. Mine is @36K right now.

Link to comment
Share on other sites

I think you mean 200000k or 200M. That's a pathetically huge amount of ram for a bloody web browser.

It really isn't. Yes, HTML/CSS/JS code is simple - that doesn't mean it costs the same amount to render.

Link to comment
Share on other sites

Firefox 3 doesn't use much ram at all. Lifehacker recently benchmarked all the browsers and firefox 3 won in memory usage.

http://lifehacker.com/5055406/browser-spee...to+date-results

even with upwards of 20-30 tabs open it hardly goes above 120 for me. You have an extension or plugin problem if it is using 200k. Try browsing in safe mode and see if it still does it. Firefox 3 does not use much memory. Chrome uses a lot more than firefox (I am using chrome as I type this post.)

Link to comment
Share on other sites

As a comparison, I do all my work via Firefox, which entails having the browser open almost 24/7, with multiple windows and many tabs open on complex pages (with multiple non-trivial extensions). It's running at 350MB as a write this, on a Vista PC with 3.5 GB of RAM.

That really ain't much, in all honesty - and it certainly doesn't impact performance.

Link to comment
Share on other sites

Knowing Mozilla, they will probably skip the thousandths, and move on to the next hundredth build. (3.0.4)

Major.Minor.BugFix

as is my understanding. All start at 0, not hundreds.

Link to comment
Share on other sites

Damn it. Why can't Firefox just issue a small patch to fix a .dll or whatever instead of releasing new version for every fix. :ermm:

Hope Mozilla fixes this soon.

Link to comment
Share on other sites

Damn it. Why can't Firefox just issue a small patch to fix a .dll or whatever instead of releasing new version for every fix. :ermm:

Hope Mozilla fixes this soon.

For general consumers, that would be a terrible idea. Not only is it confusing and prone to breaking things, you also get self-professed experts telling Joe Public to do it as well.

Link to comment
Share on other sites

was wondering why my firefox kept crashing.. I actually uninstalled all my addon's because I thought one of them was causing it. :)

Link to comment
Share on other sites

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.