AfterDawn: Tech news

Russian researcher releases attack code for Firefox 3.6 flaw

Written by James Delahunty @ 20 Feb 2010 5:37

Russian researcher releases attack code for Firefox 3.6 flaw A Russian researcher has released attack code to exploit a critical vulnerability found in Mozilla's latest version of the Firefox web browser. It triggers a heap corruption vulnerability in the open-source browser that can allow attacks to execute malicious code remotely. He added it as a module to Vulndisco, which is an add-on for the Immunity Canvas automated exploitation system sold to security professionals.
"We've played a lot with it in our labs - it was very reliable," Evgeny Legerov, founder of Moscow-based Intevydis, told The Register. "Works against the default install of Firefox 3.6. We've tested it on XP and Vista." Mozilla issued Firefox 3.5.7 (for those who haven't upgraded to Firefox 3.6 yet) during the week to address security concerns, one of which was described as a heap corruption vulnerability.



Legerov said that the bug fixed by Firefox 3.5.7 is not the same one that he is exploiting in the lab however. While currently only being available to security researchers that pay a fee, details of the attack could spread with time.

"Mozilla takes all security vulnerabilities seriously, and have as yet been unable to confirm the claim of an exploit. We value the contributions of all security researchers and encourage them to work within our security process, responsibly disclosing vulnerabilities to ensure the highest level of security and best outcome for users," Mozilla said in a statement.

Previous Next  
Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
1 user comment
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive