Jump to content

Recommended Posts

Posted (edited)

A vulnerability has been discovered in Mozilla products which can be exploited by malicious people to gain knowledge of potentially sensitive information.

 

The vulnerability is caused due to an error in the JavaScript engine, as a "lambda" replace exposes arbitrary amounts of heap memory after the end of a JavaScript string.

 

Successful exploitation may disclose sensitive information in memory.

 

http://secunia.com/mozilla_products_arbitr..._exposure_test/

 

This was discovered on April 4 and is still not patched.

Edited by carbonize
Posted

That would make no difference as the products store saved sata in a flat file. This exploit lets javascript read what is in the memory so if you have visited a web page with a form then the information you submitted is usually still in the memory. Try filling out a form, submitting it then clicking back, your data is stil in the form as it has been kept in memory (or possibly cached not 100% on that one but can't see it caching form entries)

Posted

It's already fixed on the nightly versions, which not everyone is comfortable with but nonetheless, I'm starting to be annoyed by the delays in releasing certain security fixes from the Mozilla guys... I mean, they used to be great but are they trying to become the next MS of security fixes? :)

Posted

I stopped using the nightlies a long time ago due to the fact they are making major changes which stop a lot of extensions working and I like my tab browser preferences.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...