DoS Exploit for Firefox 1.5 Released


An exploit for the new Firefox 1.5 browser was released today that causes a denial of service condition using a simple web page as a trigger. The heart of the problem lies with the history.dat file that Firefox creates, according to a posting on Packet Storm. The exploit creates a very large entry which Firefox then saves into the history.dat file. This causes the browser to crash the next time it is opened, and each time after that until the history.dat file is deleted from the system.

The author of the exploit points out that average users may have difficulty figuring out this fix, preventing browser use and effectively creating a denial of service condition. Simple DoS for Firefox 1.5

Linked by shanmuga Wednesday, 7th December 2005 9:44PM