Sorry, something went wrong while copy+pasting the repro URL:<div><a href="http://skypher.com/SkyLined/Repro/FireFox/FireFox%203.0.1%20(Build%202008070208)%20AV-Read[0]@xul!JVM_MaybeShutdownLiveConnect+0xdbe0/repro.html">http://skypher.com/SkyLined/Repro/FireFox/FireFox%203.0.1%20(Build%202008070208)%20AV-Read[0]@xul!JVM_MaybeShutdownLiveConnect+0xdbe0/repro.html</a><br>
<div><br></div><div>--------------------------------------------------------------------------------------------------------<br>Berend-Jan Wever <<a href="mailto:berendjanwever@gmail.com">berendjanwever@gmail.com</a>> <a href="http://skypher.com">http://skypher.com</a><br>
<br>
<br><br><div class="gmail_quote">On Wed, Jan 7, 2009 at 6:04 PM, Berend-Jan Wever <span dir="ltr"><<a href="mailto:berendjanwever@gmail.com">berendjanwever@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
This bug was reported by me to Mozilla in September. It is DoS only.<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=456727" target="_blank"></a><div><br></div><div><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=456727" target="_blank">https://bugzilla.mozilla.org/show_bug.cgi?id=456727</a><br>
<div><br></div><div><a href="https://bugzilla.mozilla.org/skypher.com/SkyLined/Repro/FireFox/FireFox%203.0.1%20(Build%202008070208)%20AV-Read%5B0%5D@xul!JVM_MaybeShutdownLiveConnect+0xdbe0/repro.html" target="_blank">https://bugzilla.mozilla.org/skypher.com/SkyLined/Repro/FireFox/FireFox%203.0.1%20(Build%202008070208)%20AV-Read%5B0%5D@xul!JVM_MaybeShutdownLiveConnect+0xdbe0/repro.html</a> <br>
</div><div><br></div><div>How about giving some credit where it's due?</div><div><br></div><div>Cheers,</div><div>SkyLined</div><div><br></div><div>--------------------------------------------------------------------------------------------------------<br>
<font color="#888888">
Berend-Jan Wever <<a href="mailto:berendjanwever@gmail.com" target="_blank">berendjanwever@gmail.com</a>> <a href="http://skypher.com" target="_blank">http://skypher.com</a></font><div><div></div><div class="Wj3C7c">
<br><br>
<br><br><div class="gmail_quote">On Wed, Jan 7, 2009 at 4:53 PM, carl hardwick <span dir="ltr"><<a href="mailto:hardwick.carl@gmail.com" target="_blank">hardwick.carl@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
An unpatched security flaw has been discovered in the latest version<br>
of Firefox 3.0.5 which allows a remote attacker to crash the browser<br>
with a special crafted HTML page using a queryCommandState:<br>
<br>
PoC: <a href="http://groups.google.it/group/carl-hardwick/web/Firefox305RemoteDoS.htm" target="_blank">http://groups.google.it/group/carl-hardwick/web/Firefox305RemoteDoS.htm</a><br>
<br>
_______________________________________________<br>
Full-Disclosure - We believe in it.<br>
Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">http://lists.grok.org.uk/full-disclosure-charter.html</a><br>
Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank">http://secunia.com/</a><br>
</blockquote></div><br></div></div></div></div>
</blockquote></div><br></div></div>