franzon Posted September 18, 2006 Share Posted September 18, 2006 unpatched Flaw in Firefox 1.5.0.7 PoC here lcamtuf.coredump.cx/ffoxdie.html Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/ Share on other sites More sharing options...
supernova_00 Posted September 18, 2006 Share Posted September 18, 2006 Thats old and has been fixed in the recent 1.5.0.8 release. btw it wasn't security related...just a crasher. Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/#findComment-587891611 Share on other sites More sharing options...
Marvelous Posted September 18, 2006 Share Posted September 18, 2006 i cant see any update to firefox 1.5.0.8 it might not be a ready to release build.. if so then its not officially solved yet. Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/#findComment-587891845 Share on other sites More sharing options...
zeroday Posted September 18, 2006 Share Posted September 18, 2006 Does that page have the PoC in the code of the page? I opened the link, and forgot about it, and my FF crashed! :angry: Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/#findComment-587891899 Share on other sites More sharing options...
franzon Posted September 19, 2006 Author Share Posted September 19, 2006 (edited) Thats old and has been fixed in the recent 1.5.0.8 release. NO. The latest release is Firefox 1.5.0.7 look here: http://www.mozilla.org/ btw it wasn't security related...just a crasher. Are you sure? Mozilla Firefox is prone to a remote memory-corruption vulnerability. This issue is due to a race condition that may result in double-free or other memory-corruption issues. Attackers may likely exploit this issue to execute arbitrary machine code in the context of the vulnerable application http://www.securityfocus.com/bid/19488/discuss http://www.securityfocus.com/bid/19534/discuss Edited September 19, 2006 by franzon Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/#findComment-587893687 Share on other sites More sharing options...
Boiling Ice Posted September 19, 2006 Share Posted September 19, 2006 NO. The latest release is Firefox 1.5.0.7 look here: http://www.mozilla.org/ Once you go to the download page, it still shows 1.5.0.7 Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/#findComment-587893711 Share on other sites More sharing options...
Deadlydread Posted September 19, 2006 Share Posted September 19, 2006 Just download 2.0 Rc1 Nightly which was just released :whistle: :woot: Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/#findComment-587893723 Share on other sites More sharing options...
Malisk Posted September 19, 2006 Share Posted September 19, 2006 Thats old and has been fixed in the recent 1.5.0.8 release. btw it wasn't security related...just a crasher. "Crashers" are usually (very) security related as long as the crash is due to a buffer overrun / memory corruption. They've already made a working attack based on the IE "crasher" discovered a few days ago. Simply put, if the bug can cause Firefox to run into memory preloaded with malicious code, you have a potential remote exploit. Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/#findComment-587893729 Share on other sites More sharing options...
duntkno Posted September 22, 2006 Share Posted September 22, 2006 2.0 rc1 feels like it needs a lil more work, feels slugggish. Link to comment https://www.neowin.net/forum/topic/496767-unpatched-flaw-in-firefox-1507/#findComment-587900491 Share on other sites More sharing options...
Recommended Posts