new critical vulnerability found in Firefox 3.5.1


Recommended Posts

Mozilla Firefox 3.5.1 unicode Remote Buffer Overflow

Mozilla Firefox is prone to a remote stack-based buffer-overflow vulnerability.

Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application.

Live Proof of Concept: http://www.milw0rm.com/exploit.php?id=9158

~ 1.5 GB of memory :blink:

It tries to cause an overflow but fails - either it's patched already in 3.5.1 or stack protection actually works.

Possibly if you had a machine with not much ram and out of disk/swap space, you could cause an exhaust of the clients resources but it should not crash the client even in those circumstances, only provide you with a funky out of memory error.

Edited by daPhoenix
32; this won't happen on 64 bit? :o

and please tell me that wasn't a real hack, haha. Just a proof that the damn thing exists and can be exploited.

I'm on 64bit and it doesn't crash (just lots of memory)

Only thing I can think of, is that 64Bit can do hardware DEP (well, so can 32bit in PAE mode, but nobody runs in that mode since it's buggy in the vast majority of cases), and Firefox is set to have DEP enabled (I think only Vista and Win7 will read that info, XP needs an extra function call to enable it, which is going to happen soon)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Look who's back!
    • I wonder how driving laws around the world will change. No way to really tell if people are using phone. Same with smart watches i guess even now and those silly built in tablets for controlling the car instead of buttons.
    • They found a better aligned evil overlord for WhatsApp...
    • Google Chrome 149.0.7827.197 (offline installer) by Razvan Serea The web browser is arguably the most important piece of software on your computer. You spend much of your time online inside a browser: when you search, chat, email, shop, bank, read the news, and watch videos online, you often do all this using a browser. Google Chrome is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. Use one box for everything--type in the address bar and get suggestions for both search and Web pages. Thumbnails of your top sites let you access your favorite pages instantly with lightning speed from any new tab. Desktop shortcuts allow you to launch your favorite Web apps straight from your desktop. Chrome has many useful features built in, including automatic full-page translation and access to thousands of apps, extensions, and themes from the Chrome Web Store. Google Chrome is one of the best solutions for Internet browsing giving you high level of security, speed and great features. Important to know! The offline installer links do not include the automatic update feature. Download web installer: Google Chrome Web 32-bit | Google Chrome 64-bit | Freeware Download: Google Chrome Offline Installer 64-bit | Direct Link | 131.0 MB Download: Google Chrome Offline Installer 32-bit | Direct Link | 119.0 MB Download page: Google Chrome Portable Download: Chrome ARM64 | Direct Link View: Chrome Website | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      463
    2. 2
      +Edouard
      161
    3. 3
      PsYcHoKiLLa
      112
    4. 4
      Michael Scrip
      85
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!