new critical vulnerability found in Firefox 3.5.1


Recommended Posts

Mozilla Firefox 3.5.1 unicode Remote Buffer Overflow

Mozilla Firefox is prone to a remote stack-based buffer-overflow vulnerability.

Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application.

Live Proof of Concept: http://www.milw0rm.com/exploit.php?id=9158

~ 1.5 GB of memory :blink:

It tries to cause an overflow but fails - either it's patched already in 3.5.1 or stack protection actually works.

Possibly if you had a machine with not much ram and out of disk/swap space, you could cause an exhaust of the clients resources but it should not crash the client even in those circumstances, only provide you with a funky out of memory error.

Edited by daPhoenix
32; this won't happen on 64 bit? :o

and please tell me that wasn't a real hack, haha. Just a proof that the damn thing exists and can be exploited.

I'm on 64bit and it doesn't crash (just lots of memory)

Only thing I can think of, is that 64Bit can do hardware DEP (well, so can 32bit in PAE mode, but nobody runs in that mode since it's buggy in the vast majority of cases), and Firefox is set to have DEP enabled (I think only Vista and Win7 will read that info, XP needs an extra function call to enable it, which is going to happen soon)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Meta launches new AI glasses in 26 styles and Muse Spark multimodal capabilties by Pradeep Viswanathan Meta today announced a new line of Meta Glasses in partnership with EssilorLuxottica. The new AI glasses build on the company’s existing smart glasses portfolio, which is sold under the Ray-Ban Meta and Oakley Meta brands. The new Meta Glasses start at just $299, are compatible with prescription lenses, and will be available in 26 styles across different colors, lenses, and frames. At launch, Meta Glasses will be available in three frame styles. The Meta Adventurer features a clean rectangular design and comes in Standard and Large sizes. The Meta Fury is a bolder frame for users who want a stronger look. Meta Glasses by Kylie is a slim oval frame designed in collaboration with Kylie Jenner. Similar to existing Meta AI Glasses, the new Meta Glasses include a dedicated action button that can be used to quickly access Meta AI or launch a favorite feature. They also feature open-ear speakers for calls, music, and more. Meta has also included a multi-mic array with wind noise reduction for calls and messaging. Users can capture photos and videos hands-free using voice commands. Meta claims more than eight hours of battery life, while the portable charging case can provide up to 40 additional hours. As expected, Meta Glasses come pre-loaded with Meta AI powered by Muse Spark from day one. Muse Spark is the first model from Meta Superintelligence Labs with improved multimodal capabilities. The same Meta AI upgrade is also now available on existing Ray-Ban Meta and Oakley Meta Glasses in the US and Canada via an update. With the Muse Spark-powered AI assistant, Meta AI in the new glasses can provide smarter answers, understand what the user is seeing, and help with daily tasks such as calendar management and navigation. Meta also announced an upcoming feature called the dynamic photo feature, which captures multiple frames and recommends the best one. Pedestrian navigation is also coming soon to these glasses. Meta is also adding support for 14 new live translation languages, including Japanese, Mandarin Chinese, Hindi, and Korean. The new Meta Glasses are available starting today through Meta.com, Best Buy, Amazon, LensCrafters, Sunglass Hut, and select retailers.
    • is that a personal preference? whether it is or isn't, i get where you're coming from. i try to get and use fully open sourced applications whenever i can but there are instances where i find a superior product that is closed sourced. in these cases i do my best to learn about the company, who operates it, their background, parent and sub structure etc. to some extent, depending on "the smell test". i really believe that Syncback is really and truly something great. even if you don't use it, it's always worth a recommendation to someone else, especially if that someone else is not very computer literate. for someone of your calibre you, you'll manage just fine with Syncthing, no doubt about it.
    • I agree, especially if it is cloud sourced, like this one is.. but I wouldn't say no to a local AI assistant similar to the Zettlab one which would be really helpful with my large Photos library, but also to perform tasks like installing Docker apps rather than me having to do it via Docker Compose, but I don't think we're quite there yet. Synology Photos is somewhat AI, you can ask it to search for certain people (if you have tagged them and it will attempt to match similar photos to the person) and if you put a search term in for "cars" for example, it will show you all photos with a car.
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      470
    2. 2
      +Edouard
      166
    3. 3
      PsYcHoKiLLa
      104
    4. 4
      Michael Scrip
      87
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!