News.com Mobile
for PDA or phone
Login: Forgot password? | Sign up

Unpatched Firefox 1.5 exploit made public

By Dawn Kawamoto
Staff Writer, CNET News.com
Published: December 8, 2005, 8:54 AM PST
Last modified: December 8, 2005, 1:36 PM PST

A correction was made to this story. Read below for details.

Exploit code for the latest version of open-source browser Firefox was published Wednesday, potentially putting users at risk of a denial-of-service attack.

The exploit code takes advantage of a bug in the recently released Firefox 1.5, running on Windows XP with Service Pack 2. Firefox, which initially debuted over a year ago, has moved swiftly to capture 8 percent of the browser market.

The latest Firefox flaw exists in the history.dat file, which stores information from Web sites users have visited with the Firefox 1.5 browser, according to a posting on the Internet Storm Center, which monitors online threats.

"If the topic of a page is crafted to be long enough, it will crash the browser each time it is started after going to such a page," according to the Internet Storm Center posting. "Once this happens, Firefox will be unable to be started until you erase the history.dat file manually."

In testing Firefox 1.5 without a system running McAfee security software, the Firefox 1.5 browser would stall and not respond to a user's mouse, said Johannes Ullrich, chief research officer for the Sans Institute, which runs the Internet Storm Center.

"Users have to kill out of the browser and start over again. This stalled browser creates a DOS (denial of service) condition," Ullrich said.

Packet Storm, the security group that initially published the proof-of-concept exploit code, noted that in addition to the potential denial-of-service attack that could follow a buffer overflow, systems may also be subject to a malicious execution of code.

Ullrich, however, said while the potential may exist, it has not been proven either way that malicious code could be executed.

Mozilla Foundation, which released Firefox, said it was not able to confirm the browser would crash or be at risk of a DOS attack, after visiting certain Web sites. And Mozilla has not received any reports from users of such a problem, said Mike Schroepfer, vice president of engineering for Mozilla Corp.

He added that Firefox 1.5 can be slugglish on its next start-up, due to a bug in the history.dat, but it is not a security problem.

"We have gotten no independent verification that it crashes (Firefox), but there have been a lot of attempts to try," Schroepfer said.

 
Correction: This story incorrectly stated the affiliation of Mike Schroepfer, Mozilla's results in verifying the Firefox 1.5 flaw, and the nature of the problem. Schroepfer is vice president of engineering with Mozilla Corp., and Mozilla has not been able to verify its browser can crash and lead to a denial-of-service condition. The problem itself was not a security vulnerability but actually a flaw in the browser.
 24 comments
Post a comment

TalkBack

Should change the headline

Marc D.   Dec 9, 2005, 6:37 PM PST

The contents of this article are incorrect!!!!

Bill Brock   Dec 9, 2005, 2:01 PM PST

FireFox

Eskie Eskie   Dec 9, 2005, 10:54 AM PST

Did not even know.

Charles Kompare   Dec 8, 2005, 3:03 PM PST

False bug reported or a bug that is hard to exploit

Nick Eklund   Dec 8, 2005, 2:33 PM PST

Disabling History

Keith J.   Dec 8, 2005, 9:44 AM PST

Bugs 'O Plenty

Keith J.   Dec 8, 2005, 9:43 AM PST

Now that you've scared us...

Elion Caplan   Dec 8, 2005, 9:42 AM PST

My understanding.

Matthew Good   Dec 8, 2005, 9:40 AM PST

<cough>

Ktla Knew   Dec 8, 2005, 9:17 AM PST


Did you know?

Select a tab below to set your default view.

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 9:14 PM PST
View as:
Unpatched Firefox 1.5 exploit made public Power could cost more than servers, Google warns Creative wants to make Apple pay Sober code cracked Sony says PS3 still on track for spring launch Sony fixes security hole in CDs, again Police blotter: Nude 'profile' yields Yahoo suit How tech billionaires live Intel calls MIT's $100 laptop a 'gadget' Consumers snap up LCD monitors Microsoft offers a new angle on maps Intel to battle rootkits Viacom nearing deal to acquire DreamWorks BellSouth, 8x8 launch VoIP service Cheers for Yahoo's move to a community-driven Web
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Daily spotlight

Video: A video slam-dunk

Here's a look at the tech behind those TV and online highlights of pro basketball games, in a narrated video produced by the NBA and Silicon Graphics Inc.

Photos: Gizmos made in Japan

Japan is still a leader in product design and innovation. Here are some new and notable gadgets.

Video: "The power to organize" online

Meetup.com founder and CEO Scott Heiferman says Meetup is spreading beyond America. The service, Heiferman says, is helping "make the world a friendlier place."

Innovations battle natural calamities

Scientists hope integrating cutting-edge technology projects will help predict and mitigate natural disasters.

Debating Wikipedia's open-source label

High Impact The online encyclopedia is a broadly communal effort, but it's not run the same way as open-source software.

Police blotter: Nude 'profile' yields Yahoo suit

Woman says ex-boyfriend posted nude photos and her phone number in a Yahoo Personals profile. She sued for $3 million.

High-tech animation in indies' grasp

Competing with digital toon powerhouses like Pixar isn't easy. But cheaper tech, outsourcing are making it possible.

Ogre to slay? Outsource it to China

Affluent online gamers are paying workers at Chinese game-playing factories to play games' early rounds for them.

Video: The incredible, shrinking glaciers

This NASA-produced video is a dramatic and colorful look at our planet from high above, and the changes that are taking place.

Image: AOL searches for the stars

TMZ.com, AOL's new online magazine promises inside scoops on Hollywood's hottest stars.

Clock's ticking on new Sober onslaught

Mass-mailing worm is programmed to download new instructions in January, which could indicate a new outbreak.

Photos: New animal discovered in Borneo

A creature that looks like a cross between a cat and a fox is photographed in the rainforest.

advertisement
CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use