lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <bc7e11f20901070753i21974eatec3a4432fb40471f@mail.gmail.com> Date: Wed, 7 Jan 2009 16:53:59 +0100 From: "carl hardwick" <hardwick.carl@...il.com> To: Full-Disclosure@...ts.grok.org.uk Subject: Firefox 3.0.5 remote vulnerability via queryCommandState An unpatched security flaw has been discovered in the latest version of Firefox 3.0.5 which allows a remote attacker to crash the browser with a special crafted HTML page using a queryCommandState: PoC: http://groups.google.it/group/carl-hardwick/web/Firefox305RemoteDoS.htm _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/