News.com Mobile
for PDA or phone
Login: Forgot password? | Sign up

Unpatched Firefox 1.5 exploit made public

By Dawn Kawamoto
Staff Writer, CNET News.com
Published: December 8, 2005, 8:54 AM PST
Last modified: December 8, 2005, 1:36 PM PST

A correction was made to this story. Read below for details.

Exploit code for the latest version of open-source browser Firefox was published Wednesday, potentially putting users at risk of a denial-of-service attack.

The exploit code takes advantage of a bug in the recently released Firefox 1.5, running on Windows XP with Service Pack 2. Firefox, which initially debuted over a year ago, has moved swiftly to capture 8 percent of the browser market.

The latest Firefox flaw exists in the history.dat file, which stores information from Web sites users have visited with the Firefox 1.5 browser, according to a posting on the Internet Storm Center, which monitors online threats.

"If the topic of a page is crafted to be long enough, it will crash the browser each time it is started after going to such a page," according to the Internet Storm Center posting. "Once this happens, Firefox will be unable to be started until you erase the history.dat file manually."

In testing Firefox 1.5 without a system running McAfee security software, the Firefox 1.5 browser would stall and not respond to a user's mouse, said Johannes Ullrich, chief research officer for the Sans Institute, which runs the Internet Storm Center.

"Users have to kill out of the browser and start over again. This stalled browser creates a DOS (denial of service) condition," Ullrich said.

The author of the proof-of-concept exploit code, initially published by nonprofit group Packet Storm, claimed the glitch is a buffer overflow that could lead to a denial-of-service attack and may even be used for a malicious execution of code. Packet Storm itself said a possible denial-of-service condition exists.

Ullrich, however, said while the potential may exist, it has not been proven either way that malicious code could be executed.

The Mozilla Foundation, which released Firefox, said it was not able to confirm the browser would crash or be at risk of a DOS attack, after visiting certain Web sites. And Mozilla has not received any reports from users of such a problem, said Mike Schroepfer, vice president of engineering for Mozilla Corp.

He added that Firefox 1.5 can be slugglish on its next start-up, due to a bug in the history.dat, but it is not a security problem.

"We have gotten no independent verification that it crashes (Firefox), but there have been a lot of attempts to try," Schroepfer said.

 
Correction: This story incorrectly stated the affiliation of Mike Schroepfer. It also misstated Mozilla's results in verifying the Firefox 1.5 flaw. The problem itself was not a security vulnerability but actually a flaw in the browser, according to Mozilla. In addition, it misstated PacketStorm's assessment of the situation.
 26 comments
Post a comment

TalkBack

firefox - What a joy to use.

Grey Eminence   Dec 13, 2005, 6:55 AM PST

Should change the headline

Marc D.   Dec 9, 2005, 6:37 PM PST

The contents of this article are incorrect!!!!

Bill Brock   Dec 9, 2005, 2:01 PM PST

FireFox

Eskie Eskie   Dec 9, 2005, 10:54 AM PST

Did not even know.

Charles Kompare   Dec 8, 2005, 3:03 PM PST

False bug reported or a bug that is hard to exploit

Nick Eklund   Dec 8, 2005, 2:33 PM PST

Disabling History

Keith J.   Dec 8, 2005, 9:44 AM PST

Bugs 'O Plenty

Keith J.   Dec 8, 2005, 9:43 AM PST

Now that you've scared us...

Elion Caplan   Dec 8, 2005, 9:42 AM PST

My understanding.

Matthew Good   Dec 8, 2005, 9:40 AM PST

<cough>

Ktla Knew   Dec 8, 2005, 9:17 AM PST

advertisement

Did you know?

Select a tab below to set your default view.

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 10:11 AM PST
View as:
Google whistles a new tune Compliance laws boosting IT budgets Is Stern worth his millions? Faux Hulks can keep fighting evil online 'King Kong' not so mighty on Xbox 360, standard TVs Google home pages get even more personal Quanta to build the $100 laptop Bringing prime time to video iPod Apple settles with third alleged Tiger leaker In search of the Wikipedia prankster Kazaa owners may face time in jail Senate panel approves more Net-policing powers Microsoft to reorg entertainment division Analyze your handwriting on this page The wide world of Google
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Daily spotlight

Perspective: How to lose friends and alienate people

Law professor Tim Wu sees tech companies making wrong choices when it comes to their customers.

Bringing prime time to the video iPod

NBC's and TiVo's future plans aside, software allows users to take their recorded TV shows with them today.
Video: New content for iPod

Year in review: Big battles for big talent

Concerns remain over outsourcing and guest workers, but hiring prospects have improved for skilled workers.

Is Stern worth his millions?

Satellite radio will likely make back Stern's $500 million paycheck, but his post-decency patter remains a wild card.
Audio: Will Stern fly?

New 'Kong' monkeys with game industry

Peter Jackson's "King Kong" and the new movie-based game are blurring lines between where stories begin and end.
Video: Kong vs. T-Rex
Images: A beast of a game

Quanta to build the $100 laptop

World's largest laptop manufacturer will make the low-cost box championed by Massachusetts Institute of Technology.

Perspective: Holiday shoppers, beware

Attorney Eric J. Sinrod warns of an imminent parade of horribles: identity theft, viruses, phishing, worms and spyware.

Photo: The 'Urge' to play Xbox

Nissan's plans for its Urge Concept sports car include a built-in Xbox gaming system.

Keyboard carpal culprit?

Not so, study says A new research report says heavy computer use does not lead to carpal tunnel syndrome.

RFID goes to college

Indiana University, University of California at Irvine add business courses in electronic-identification technology.

Photos: Xbox 360 lands in Japan

Microsoft brings its next-generation game console to the home turf of rivals Sony and Nintendo.

Photos: Asimo learns new tricks

Honda's humanoid robot is faster than ever and ready to help out around the office.


CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use