PDA

View Full Version : Image Processing Flaw Found in Firefox .



peat moss
05-19-2006, 01:32 AM
http://img317.imageshack.us/img317/9608/untitled35hf.gifFirefox users may be vulnerable to a denial of service attack after researchers looked into reports of a new vulnerability within Firefox 1.5.0.3. The flaw exists in how the browser handles image tags. The SANS Internet Storm Center first wrote off the problem, but continued research has shown that the flaw could be used maliciously.

The exploit was initially believed to only be a joke, as a hyperlinked "image" when opened would launch the media player and play a .wav file. However, researchers now say the same flaw could be used in conjunction with JavaScript to open a mail client and open up multiple windows using the "mailto:" command.

:source: Source: http://www.betanews.com/article/Image_Processing_Flaw_Found_in_Firefox/1147893245

Dedalus^
05-19-2006, 01:38 AM
So, as long as we dont click a hyperlinked "image", we're safe correct?

And only 1.5.0.3 is affected right?

peat moss
05-19-2006, 01:56 AM
So, as long as we dont click a hyperlinked "image", we're safe correct?

And only 1.5.0.3 is affected right?


I not sure but it does give a fix tho not a good one :

"One possible workaround is to turn off automatic startup of your e-mai application in Firefox," he said. Additionally, a user could disable JavaScript, or block "mailto:" altogether.

twisterX
05-19-2006, 02:57 AM
NEW NEWS TOWMORRO

Firefox Update Released!!! :D

peat moss
05-19-2006, 03:15 AM
NEW NEWS TOWMORRO

Firefox Update Released!!! :D

Its about bloody time ! :lol: JK ,FF seems to do fine with the security problems . Is open source that much more responsive or just more people working on the quirks and tweaks ?