Hi all,
Research and development has let to a ~90% reliable working exploit for the
IDN Heap Buffer overrun in FireFox on WinXP and Win2k3 as long as DEP is
turned off and JavaScript is enabled. Some tweaking might yield an even
higher success ratio. It has also revealed that not only FireFox is
vulnerable to this vulnerability, but the exact same exploit works on the
latest releases of all these products based on the Mozilla engine:
- Mozilla FireFox 1.0.6 and 1.5beta,
- Mozilla Browser 1.7.11,
- Netscape 8.0.3.3 <http://8.0.3.3>.
Recommendations for this vulnerability:
- FireFox and Mozilla: Install the workaround for (
- Netscape: hope they'll respond to this email and release a workaround.
- Wait for a patch and install it asap.
Recommendations to make it harder to exploit any FireFox vulnerability:
- Turn on DEP (Data Execution Prevention),
- Turn off JavaScript,
- Switch to another browser,
- Do not browse untrusted sites,
- Do not browse the web at all,
- Unplug your machine from the web,
- Wear a tinfoil hat.
Cheers,
SkyLined