new critical vulnerability found in Firefox 3.5.1


Recommended Posts

Mozilla Firefox 3.5.1 unicode Remote Buffer Overflow

Mozilla Firefox is prone to a remote stack-based buffer-overflow vulnerability.

Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application.

Live Proof of Concept: http://www.milw0rm.com/exploit.php?id=9158

~ 1.5 GB of memory :blink:

It tries to cause an overflow but fails - either it's patched already in 3.5.1 or stack protection actually works.

Possibly if you had a machine with not much ram and out of disk/swap space, you could cause an exhaust of the clients resources but it should not crash the client even in those circumstances, only provide you with a funky out of memory error.

Edited by daPhoenix
32; this won't happen on 64 bit? :o

and please tell me that wasn't a real hack, haha. Just a proof that the damn thing exists and can be exploited.

I'm on 64bit and it doesn't crash (just lots of memory)

Only thing I can think of, is that 64Bit can do hardware DEP (well, so can 32bit in PAE mode, but nobody runs in that mode since it's buggy in the vast majority of cases), and Firefox is set to have DEP enabled (I think only Vista and Win7 will read that info, XP needs an extra function call to enable it, which is going to happen soon)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • hands down the worst version of Windows to date and sadly I think it's only downhill from here
    • I've never known a release to have so much pressure than this one. There is so much riding on the whole games industry because of everything that's changed in the past five years. That if this is a complete flop then I think the whole games industry is done unless something radically changes.
    • Windows 11 is now five years old by Taras Buria Windows 11 is now half a decade old. Five years ago, on June 24, 2021, Microsoft announced its latest operating system, designed to "bring you closer to what you love." Today, Windows 11 celebrates its fifth birthday. The launch of Windows 11 was interesting. Rumors about Microsoft introducing a Windows 10 successor popped up weeks before the public announcement, and a few days later, an entire preview build leaked online, allowing everyone to take a peek at what Microsoft was preparing. A few weeks later, Microsoft confirmed that Windows 11 was a thing and officially unveiled its next-gen operating system. Early versions of Windows 11 promised quite a lot. A redesigned, more modern user interface, a brand new Start menu and taskbar, improvements to virtual desktops and window snapping, Android app support, Teams integrated into the taskbar, Windows Widgets, a new version of the Microsoft Store, improved security, and more. Some of those features were welcomed, while others were received with heavy criticism. Besides missing taskbar and Start menu features, many disliked the steep hardware requirements, which kicked out PCs that were back then still perfectly fine. TPM and Secure Boot became mandatory, causing a spike in sales of dedicated TPM chips for motherboards. Double-layered context menus were disliked as well, and it is something that Microsoft still has to fix. Additionally, with time, some of Windows 11's exclusive features were simply killed. Microsoft removed the Teams integration and discontinued Android app support. During the early days of Windows 11, Microsoft was quite unwilling to address things that users criticized most. After four years on the market, management changes, and heated competition from the Mac camp, Microsoft finally decided to give in and take its operating system back to the drawing board to fix everything users had been complaining about for years. Microsoft is now redesigning the Start menu, adding missing taskbar features, improving Windows Update, fixing Windows 11's context menu, and more. Some believe all that warrants a new Windows 12 release, but for now, it appears that Windows 11 will stick around for a while. With Microsoft now listening to its core audience and acting upon received feedback, fans can finally expect a much better version of Windows 11 than what was available five years ago. Here is to five more years, Windows 11!
    • It’s a code which will be connected to your account. You can share the box but that would be sort of pointless.
  • Recent Achievements

    • Week One Done
      Wavespace earned a badge
      Week One Done
    • One Year In
      OHI Accounting earned a badge
      One Year In
    • First Post
      Almohandis earned a badge
      First Post
    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      463
    2. 2
      +Edouard
      176
    3. 3
      PsYcHoKiLLa
      122
    4. 4
      Michael Scrip
      82
    5. 5
      Xenon
      75
  • Tell a friend

    Love Neowin? Tell a friend!