[Full-disclosure] Firefox 3.0.8 remote DoS: 0-day exploit

2009-04-04 Thread Nick
This has already been posted on Firefox's bugzilla ( https://bugzilla.mozilla.org/show_bug.cgi?id=456727) and there is another bug like this one that causes firefox to hang ( https://bugzilla.mozilla.org/show_bug.cgi?id=348033). The 0day exploit/bug is fixed and its been committed to the CVS and wi

[Full-disclosure] [SECURITY] [DSA 1761-1] New moodle packages fix file disclosure

2009-04-04 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-1761-1secur...@debian.org http://www.debian.org/security/ Nico Golde April 3rd, 2009

Re: [Full-disclosure] Firefox 3.0.8 remote DoS: 0-day exploit

2009-04-04 Thread Paul Schmehl
--On April 4, 2009 2:39:40 PM +0200 carl hardwick wrote: > I found an unpatched vulnerability in the latest Firefox 3.0.8 allows > a remote attacker to cause a DoS. > A 0-day exploit is available here: > http://carl-hardwick.googlegroups.com/web/Firefox+3.0.8+DoS.htm?gda=i_oP > fkcAAACkS-ZCh60y1

[Full-disclosure] [ GLSA 200904-04 ] WeeChat: Denial of Service

2009-04-04 Thread Tobias Heinlein
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200904-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

Re: [Full-disclosure] Firefox 3.0.8 remote DoS: 0-day exploit

2009-04-04 Thread Mike Bann
I highly doubt you reported this to Mozilla in "September of 2009". I don't think time machines like that exist yet, but i'd be pleased to be wrong. Berend-Jan Wever wrote: > ...sigh > > This is https://bugzilla.mozilla.org/show_bug.cgi?id=456727, which I > reported to Mozilla in September

Re: [Full-disclosure] Firefox 3.0.8 remote DoS: 0-day exploit

2009-04-04 Thread Berend-Jan Wever
...sigh This is https://bugzilla.mozilla.org/show_bug.cgi?id=456727, which I reported to Mozilla in September of 2009. It is a NULL ptr DoS, there is no "exploit" in the sense of executing arbitrary code, just a "repro" that can trigger a crash. The repro provided by Carl is the exact same rep

[Full-disclosure] Firefox 3.0.8 remote DoS: 0-day exploit

2009-04-04 Thread carl hardwick
I found an unpatched vulnerability in the latest Firefox 3.0.8 allows a remote attacker to cause a DoS. A 0-day exploit is available here: http://carl-hardwick.googlegroups.com/web/Firefox+3.0.8+DoS.htm?gda=i_oPfkcAAACkS-ZCh60y1HGkG90OfxntdaCvR5MIFXIiKOQt5O80jPqLKEFpBrbag3mOAa49_d8xnmtLTzx06f-L8nRU