Securityview
Poll

    What's your opinion about the actions of DieselScripts?

    See this story if you missed it!


    View Results

    View or give your comment

Active Virus Alerts by Kaspersky
  • updated:01 Jan 1970 12:00am UTC

  • If empty no active alerts are available!

Securityview 5 currently online
199 maximum concurrent
275745 total visitors

Firefox Marquee bug

A few days ago we saw a notice on a mailinglist about a PoC which makes a DoS possible on (again) Firefox. We contacted the guy who posted it (n00b) and asked him what it does.

It seems like it uses an old bug in Firefox, it exploits the way Firefox handles multiple html tags.

We’ve tested this on Windows XP without Service Packs, with SP1 and SP2 and it crashes Firefox. On Linux however it spikes the load, but it doesn’t crash Firefox, and on my Apple (Mac OS X Version 10.4.6) it does the same as on Linux.

But this doesn’t mean that it isn’t a bad bug, and the Firefox developers really need to get this fixed.

The PoC is available here, but remember that it can crash your Firefox!

2 Responses to “Firefox Marquee bug”

Leave a Reply