Exploits and Security

Technology & Security Tips & Guides

Gentoo Linux Security Advisory GLSA 200507-17
- - - - - - - - - - - - - - - - - - - - - - - - [...]

Problem Description:
A number of vulnerabilities were reported and fixed in Firefox 1.0.5
and Mozilla 1.7.9. The following vulnerabilities have been backported
and patched for this update:
In several places the browser UI did not correctly distinguish between
true user events, such as mouse clicks or keystrokes, and synthetic
events genenerated by web content. [...]

Vendor:
Mozilla (http://www.mozilla.org)
Vulnerable Software:
Mozilla 1.7.8
Firefox 1.0.4
Camino 0.8.4
Vulnerability/Exploit:
By using a specially crafted JavaScript function, it is possible to
crash the above named browsers. The script can be executed both with and
without user intervention.
Proof of Concept:
—–START of PoC—–

//Run the function 20000 times
[...]