Mozilla Firefox Range Script Object Denial of Service Vulnerability
BID:20799
Info
Mozilla Firefox Range Script Object Denial of Service Vulnerability
| Bugtraq ID: | 20799 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2006 12:00AM |
| Updated: | Nov 28 2006 04:45PM |
| Credit: | Carlos Barros is credited with discovering this vulnerability. |
| Vulnerable: |
Mozilla SeaMonkey 1.1 beta Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 .6 Mozilla Firefox 1.5 Mozilla Firefox 1.0.8 Mozilla Firefox 1.0.7 Mozilla Firefox 1.0.6 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.4 Mozilla Firefox 1.0.3 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox 2.0 RC3 Mozilla Firefox 2.0 RC2 Mozilla Firefox 2.0 beta 1 Mozilla Firefox 2.0 Mozilla Firefox 1.5.0.7 Mozilla Firefox 1.5.0.6 Mozilla Firefox 1.5.0.5 Mozilla Firefox 1.5.0.4 Mozilla Firefox 1.5.0.3 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.1 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox Range Script Object Denial of Service Vulnerability
Mozilla Firefox is prone to a remote denial-of-service vulnerability.
An attacker may exploit this vulnerability to cause Mozilla Firefox to crash, resulting in denial-of-service conditions.
Mozilla Firefox 1.5.0.7 (and earlier) as well as version 2.0 are prone to this issue.
Mozilla Firefox is prone to a remote denial-of-service vulnerability.
An attacker may exploit this vulnerability to cause Mozilla Firefox to crash, resulting in denial-of-service conditions.
Mozilla Firefox 1.5.0.7 (and earlier) as well as version 2.0 are prone to this issue.
Exploit / POC
Mozilla Firefox Range Script Object Denial of Service Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Mozilla Firefox Range Script Object Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Mozilla Firefox Range Script Object Denial of Service Vulnerability
References:
References:
- Bugzilla Bug 358797 (Daniel Veditz
) - Gotfault Security - Advisory #05 - 27/10/06 (Carlos Barros
) - Mozilla Homepage (Mozilla Foundation)
- Re: New Flaw in Firefox 2.0: DoS and possible remote code execution ([email protected])
- Re: New Flaw in Firefox 2.0: DoS and possible remote code execution (Daniel Veditz
)