Mozilla Firefox IFRAME Handling Denial Of Service Vulnerability
BID:15015
Info
Mozilla Firefox IFRAME Handling Denial Of Service Vulnerability
| Bugtraq ID: | 15015 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2005 12:00AM |
| Updated: | Oct 05 2005 12:00AM |
| Credit: | Discovery is credited to Tom Ferris. |
| Vulnerable: |
Mozilla Firefox 1.0.7 Mozilla Firefox 1.0.6 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox IFRAME Handling Denial Of Service Vulnerability
Mozilla Firefox is prone to a remote denial of service vulnerability.
The vulnerability presents itself when an affected browser handles a specially crafted IFRAME.
A successful attack may result in crashing the application, or consuming excessive CPU and memory resources of computers running the affected application.
It should be noted that this issue was reported to affect Firefox 1.0.6 and 1.0.7 running on Linux. Other versions running on different platforms may be vulnerable as well.
Mozilla Firefox is prone to a remote denial of service vulnerability.
The vulnerability presents itself when an affected browser handles a specially crafted IFRAME.
A successful attack may result in crashing the application, or consuming excessive CPU and memory resources of computers running the affected application.
It should be noted that this issue was reported to affect Firefox 1.0.6 and 1.0.7 running on Linux. Other versions running on different platforms may be vulnerable as well.
Exploit / POC
Mozilla Firefox IFRAME Handling Denial Of Service Vulnerability
The following proof of concept is available:
IFRAME WIDTH=33333333
The following proof of concept is available:
IFRAME WIDTH=33333333
Solution / Fix
Mozilla Firefox IFRAME Handling Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mozilla Firefox IFRAME Handling Denial Of Service Vulnerability
References:
References:
- Bugzilla Bug 303433 - Firefox 1.0.6 segfaults on this malformed .html page (Mozilla)
- Firefox 1.0.7 IFRAME Float Stack Overflow (Security-Protocols.com)
- Mozilla Firefox Home Page (Mozilla)