Another Denial of Service Bug Found in Firefox 2 206
An anonymous reader writes "A second security flaw that could cause the new Firefox 2 browser to crash
has been publicly disclosed.
The vulnerability lies in the way the open-source browser handles
JavaScript code. Viewing a rigged Web page will cause the browser to exit,
a representative for Mozilla, the publisher of the software, said
Wednesday. Contrary to claims on security mailing lists, the bug cannot be
exploited to run arbitrary code on a PC running Firefox 2, the
representative said.
This flaw in the JavaScript Range object is different than the
denial-of-service vulnerability in Firefox 2 that was confirmed by Mozilla
last week. That bug is related to a more serious security hole, which was
fixed in earlier versions of Firefox, the organization has said.
The two 'crashers' are the only publicly released vulnerabilities that
have been confirmed by Mozilla in the week since Firefox 2 was launched.
The issues are only minor, the organization has said."