Oct 3 2006

Firefox JavaScript security “a complete mess”? More like a hoax

  • Written by soulxtc
  • No Comments

Mozilla has been able to reproduce a DoS issue based on the information, according to a new post on the Mozilla Developer Center. So far, they have yet to determine whether code execution is a possibility, but say they are “still investigating” and promise updates as necessary. Nevertheless, it’s beginning to look as though this was largely a prank.

Mischa Spiegelmock has now said that the talk “was to be humorous,” and that the presentation covered a “previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution.” In other words, they didn’t discover a new flaw.

Spiegelmock said that the code they presented to attendees does not not actually work, lowering fears that a true zero-day exploit could be in the wild. To make matters more embarrassing, Spiegelmock also said that no one has successfully executed arbitrary code using the attack. “I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven’t used it to take over anyone else’s computer and execute arbitrary code,” according to comments on Mozilla’s developers blog.

As to the claim that there are 30 known exploits in Firefox, Spiegelmock said that the claim was made only by Wbeelsoi, and indicated that it, too, has not been verified.

READ REST OF ARTICLE

Related Posts

  1. Firefox a “complete security mess”
  2. FireFox Spyware Hoax Spreads
  3. Mozilla Announces Firefox 1.0.1
  4. Firefox 1.5.0.5 update plugs ‘critical’ holes
  5. Firefox 1.0.7 Released
Zeropaid on Facebook

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

Trackbacks url:

Leave a Comment...

Giganews Newsgroups


1 Star2 Stars3 Stars4 Stars5 Stars Loading ... Loading ...

  • @TheHuxCapacitor: Hmmm, Couple of things for me - There's no causal relationship proven in the study between P2P and decline in sales...
  • Stan: I would love to get Ayn Rand's perspective on this situation. The labels may have changed, but the selfishness, ...
  • soulxtc: Actually no. See this > http://i64.photobucket.com/albums/h187/soulxtc/ip... (From http://www.zeropaid.com/news/10021...
  • soulxtc: Actually no. See this > http://i64.photobucket.com/albums/h187/soulxtc/ip... (From http://www.zeropaid.com/news/10021...
  • PekkaK: The discussion about copyright has long ago transcended the question of whether anyone has the right to steal or copy or...
  • Debbie: hi could I please get an invite please. I was a member of Demonoid but is down.Thanks. ...
  • D.AN: "... the basic system [...] is Capitalist. Trying to change that [...] just means there will be a lot of corporation own...
  • D.AN: You seem to have the misinformation that file-sharers are part of one group. However, that is not true. "Even ideas, ...
  • sdsd