If at first you don't succeed; call it version 1.0
Sunday, December 11, 2005

A few days ago, ZIPL0CK introduced a new Denial Of Service vulnerability in Firefox. By creating a huge web page title, which will fill the history.dat file with large content, Firefox will hang for some time (depending the content size and the user's system) on the next time the user will try to use the browser.

Today, Mozilla foundation published an advisory, claiming this issue is not so serious, and that the unresponsiveness of the browser is only "temporary". This is true for the Proof-of-Concept exploit, and for people with strong computers. But by modifying the PoC, an attacker can easily achieve a humongous history.dat file which will cause the Firefox to hang (with 100% CPU utilization) for a LONG LONG time. So long, that most users will not wait just to delete the history as suggested by Mozilla foundation in the advisory. The right workaround would be to delete the history.dat file. Moreover, Mozilla foundation should acknowledge this problem as more severe, and address it as soon as possible.

This reminds me the last time Mozilla underestimated a vulnerability. I've also posted this issue to Full-Disclosure, but yet to receive response from Mozilla. 

I think it's been enough time for people to upgrade from v1.0.4. of Firefox. So, here is the PoC exploit for the InstallVersion.compareTo() vulnerability. The PoC does nothing but returns (this can be easily replaced with shell code), and it uses SkyLined's InternetExploiter2 methodology to inject code to the heap.

[UPDATE:] Apparently, Mozilla team has removed the access to the InstallVersion.compareTo() bug report page. I hope this means they will finally set the severity of this security hole in the advisory to higher than just 'Moderate'.

[Another Update:] Packetstorm has removed the Denial-of-Service exploit page. This PoC can be found at milw0rm.

[Last Update? :] The InstallVersion.compareTo() bug report page is opened again. Unfortunately, the severity of the vulnerability in the advisory is still 'Moderate' :(.

[Last Update! :] Victory! Well, Sort Of..


Sunday, December 11, 2005 1:36:24 PM UTC | Comments [10] | Security#
Tuesday, December 13, 2005 10:14:15 AM UTC
Wat ben jij een lul!
Marc
Tuesday, December 13, 2005 10:54:48 AM UTC
English please...
Aviv Raff
Tuesday, December 13, 2005 5:51:24 PM UTC
"Wat ben jij een lul!" - You're such a dick (http://babelfish.altavista.com/)

A Dutch news announcement has been made at http://webwereld.nl/articles/38797

A compareTo() Remote Code Execution Exploit has been published at http://www.milw0rm.com/id.php?id=1369

At your service!
Vix
Tuesday, December 13, 2005 6:31:08 PM UTC
lol .. and they say firefox is safe? muwhahaha .. dont make me laugh :p
xanadu
Wednesday, December 14, 2005 12:55:38 AM UTC
I made bug 295854 public again. Sorry about that; I think I made it private accidentally.
Wednesday, December 14, 2005 3:58:53 AM UTC
You know, you could have gone to jail for this...
Wednesday, December 14, 2005 1:39:39 PM UTC
No he couldn't... it's a bug in the program that needed to be fixed.

And the level is at Critical now. ;)
stev0
Wednesday, December 14, 2005 2:51:32 PM UTC
Funny... there is a 'copyright' in your 'code'. Get a life, jackass.
Wednesday, December 14, 2005 3:02:21 PM UTC
Peter, the "copyright" is a reminder to "Exploits Databases" (like milw0rm/FrSirt etc.) not to remove my name. That's all.
Aviv Raff
Thursday, January 11, 2007 1:31:39 PM UTC
Came across this code "in the wild" today (2007-01-11), apparently from an "advertisement" pop-under that got opened by going to an ImageShack link. Currently it's at http://www.bpath.com/bannerexchange/hotbar/cr-4518.html (inside the frame the exploit is at http://125.212.47.244/ff.htm

Makes me wonder if they are going for people who haven't updated their Mozilla/Firefox installs?

Anyway, since I found your copyright notice and URL in the code, I thought you would maybe find it interesting :-)
Comments are closed.     
Send me an Email
Follow me on Twitter
RSS Feeds
  
Blogroll
Archive
Admin Login
Sign In
Disclaimer
The opinions expressed herein are my own personal opinions and do not represent my employer's view in anyway.