[Full-disclosure] Firefox onUnload + document.write() memory corruption vulnerability (MSIE7 null ptr)

Stan Bubrouski stan.bubrouski at gmail.com
Sun Feb 25 16:57:47 GMT 2007


On 2/25/07, Daniel Veditz <dveditz at cruzio.com> wrote:
> Michal Zalewski wrote:
> > A quick test case that crashes while trying to follow partly
> > user-dependent corrupted pointers near valid memory regions (can be forced
> > to write, too):
> >
> >   http://lcamtuf.coredump.cx/ietrap/testme.html
> >
> > Firefox problem is being tracked here:
> >   https://bugzilla.mozilla.org/show_bug.cgi?id=371321
>
> This bug was fixed in 2.0.0.2, released Friday Feb 23.

No it most certainly wasn't, do your homework next time.

-sb




Full-Disclosure is hosted and sponsored by Secunia.