Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Another Denial of Service Bug Found in Firefox 2 206

An anonymous reader writes "A second security flaw that could cause the new Firefox 2 browser to crash has been publicly disclosed. The vulnerability lies in the way the open-source browser handles JavaScript code. Viewing a rigged Web page will cause the browser to exit, a representative for Mozilla, the publisher of the software, said Wednesday. Contrary to claims on security mailing lists, the bug cannot be exploited to run arbitrary code on a PC running Firefox 2, the representative said. This flaw in the JavaScript Range object is different than the denial-of-service vulnerability in Firefox 2 that was confirmed by Mozilla last week. That bug is related to a more serious security hole, which was fixed in earlier versions of Firefox, the organization has said. The two 'crashers' are the only publicly released vulnerabilities that have been confirmed by Mozilla in the week since Firefox 2 was launched. The issues are only minor, the organization has said."
This discussion has been archived. No new comments can be posted.

Another Denial of Service Bug Found in Firefox 2

Comments Filter:
  • Old times (Score:5, Insightful)

    by managementboy ( 223451 ) on Thursday November 02, 2006 @03:10AM (#16685441) Homepage
    It used to be that if one an application crashed and it was called just that: it crashed. Today its a DOS attack! Imagine how many DOS my old Windows 3.11 had... come to think of it, it only had one DOS.

    We present "DOS reloaded"!
  • Re:LOL IE Users! (Score:4, Insightful)

    by Mikachu ( 972457 ) <burke.jeremiahj@gmail . c om> on Thursday November 02, 2006 @03:32AM (#16685571) Homepage
    Except let's see how long it takes for the Firefox team to patch up these flaws as opposed to IE.
  • Re:Old times (Score:5, Insightful)

    by cperciva ( 102828 ) on Thursday November 02, 2006 @03:52AM (#16685651) Homepage
    It used to be that if one an application crashed and it was called just that: it crashed. Today its a DOS attack!

    Not necessarily. Application-crashing bugs are Denial of Service bugs if they can be triggered remotely.

    There's a fundamental difference between "I can make my copy of FireFox crash" and "I can make your copy of FireFox crash".
  • Re:Old times (Score:4, Insightful)

    by jesser ( 77961 ) on Thursday November 02, 2006 @05:49AM (#16686109) Homepage Journal
    More to the point, there's a fundamental difference between "I can make your copy of Firefox crash when you visit my site" and "I can make your copy of Apache crash".

    Crash bugs in client software such as web browsers are "crashes", not "DoS vulnerabilities".
  • Re:So funny (Score:3, Insightful)

    by snero3 ( 610114 ) on Thursday November 02, 2006 @07:50AM (#16686711) Homepage

    Personally I think the comments you are referring to come from a number of different factors

    1. Microsoft is often not the one to admit the security flaw. Where as Mozilla/firefox community is.
    2. Often Microsoft will denie the flaw pointed out in point number 1
    3. There have been numerous occurrences where an IE bug has allowed a whole PC to be taken over from bug that either MS denies exists or is very slow to patch. Holes like that in firefox generally get patched well before it is public knowledge.
    4. for the longest time IE was the ONLY browser that would work properly on a windows environment and MS thought that was a "fair and just" way to do business.
    5. Firefox is OSS, so you can go in there and fix/find the bug yourself where as with IE you have to rely on MS fixing it for you.

    As for you issues with it crashing I think that is a bit personal/related to your system? Come on! you swapped to a completed different browser after little over a week of use? I personal run firefox 2 on OS X, windows XP/2000 and Linux (FC4,RHEL4u3) and have had not problems on any platform, but maybe that is just me.

  • Comment removed (Score:3, Insightful)

    by account_deleted ( 4530225 ) on Thursday November 02, 2006 @09:23AM (#16687375)
    Comment removed based on user account deletion
  • Re:LOL IE Users! (Score:3, Insightful)

    by Richard Steiner ( 1585 ) <rsteiner@visi.com> on Thursday November 02, 2006 @11:45AM (#16689195) Homepage Journal
    Make no mistake, a lot of people on here aren't so much pro-OSS as they are anti-MS.

    Of course. Remember that many of the PC hobbyists on this site predate the general acceptance of the FOSS movement, and that many of us remember Microsoft from their DOS and Win 3.1 days as well as their more recent attempts at world domination.

    After 20 years of dealing with that company, one tends to develop well-entrenched opinions about the quality of their software and the ethics (or lack thereof) behind Microsoft's business practices.

Anyone can make an omelet with eggs. The trick is to make one with none.

Working...