[Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-24 Thread Berend-Jan Wever
Hi all, Same flaw works for Firefox as well as MSIE: a = new Array(); while (1) { (a = new Array(a)).sort(); } a = new Array(); while (1) { (a = new Array(a)).sort(); } Added to the list: http://www.edup.tudelft.nl/~bjwever/advisory_firefox_flaws.html I'd have loved to CC mozilla abo

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-25 Thread Juan Carlos Navea
> So instead you unleash it upon kiddie and spammer world? That's lovely. > Next you will come by again and say: "I'm still hoping I get to see the > guy who wrote those MyDoom worms in court, he violated the GPL and > spread millions(?) of copies of my (modified) source)." > So, you release it l

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-25 Thread Heikki Toivonen
Berend-Jan Wever wrote: I'd have loved to CC mozilla about this, but I didn't have the time to do the crash course "how to write a bug report" and go through all that bugzilla crap. Well, Mozilla does have a well know security email alias for those who don't have the time to do a crash course on B

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-26 Thread Jose Nazario
On Thu, 25 Nov 2004, Heikki Toivonen wrote: > 3. Either login if you already have an account, or click "create new > account". Let's assume we need to create a new account... > 4. Type in a valid email address and click "Create Account" > 5. [mail] Read email that was sent to the address to get pa

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-27 Thread Heikki Toivonen
Jose Nazario wrote: On Thu, 25 Nov 2004, Heikki Toivonen wrote: 3. Either login if you already have an account, or click "create new account". Let's assume we need to create a new account... requiring someone to register to post a bug is harmful in the sense that you wind up turning off peopl ewho

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-29 Thread exon
Jose Nazario wrote: On Thu, 25 Nov 2004, Heikki Toivonen wrote: 3. Either login if you already have an account, or click "create new account". Let's assume we need to create a new account... 4. Type in a valid email address and click "Create Account" 5. [mail] Read email that was sent to the addre

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-29 Thread Esben Stien
Jose Nazario <[EMAIL PROTECTED]> writes: > requiring someone to register to post a bug is harmful in the sense that > you wind up turning off peopl ewho simply can't be bothered to fill out > that info Exactly. -- Esben Stien is [EMAIL PROTECTED] http://www.esben-stien.name irc://irc.esben-sti

Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception

2004-11-29 Thread Daniel Veditz
Jose Nazario wrote: > benefits of forcing/encouraging registration include: > - garaunteed line of followup > - reduced spam quantities in bugzilla > - at leasta cutofof "i care enough to ..." Currently more than half of the bugs that do get filed end up wasting time rather than