This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Firefox [removed] Vuln - workaround available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1327
Last Updated: 2006-05-11 11:50:09 UTC
"…PoC DoS exploit, which uses the recently discussed Firefox 1.5.0.3 image issue*… (PoC) exploit will use javascript to generate image tags with 'mailto:' link, which in turn will open the mail application automatically without any user interaction. As a result, many mail windows (e.g. Outlook) will be opened and the system will become unresponsive.
One possible workaround is to turn off automatic startup of your e-mail application in Firefox. To do so, enter in the URL bar: about:config . This will show a long list of configuration options. Search for 'warn-external.mailto' (e.g. use the 'Filter' option). By default, this value should be set to "false". Click on the line to toggle it to "true" (it will be bold if it is not set to the default).
Now, whenever you click on a mailto: link, you will first be asked if you would like to start your e-mail application. In the case of the exploit this will keep your system responsive, even though you may still have to click on all the dialogs.
Disabling javascript is another option, or disabling mailto: link all together. But these options are more intrusive…"

* https://isc.sans.org/diary.php?storyid=1316

:ph34r: :huh:
FYI…

- http://secunia.com/advisories/20244/
Release Date: 2006-05-23
Critical: Not critical
Impact: Exposure of system information
Where: From remote
Solution Status: Unpatched…
…The weakness is caused due to file path information being included in certain exceptions being thrown by the browser. This can e.g. be exploited to disclose the full installation path by calling the "window.sidebar.addSearchEngine()" JavaScript function with invalid parameters.
This may reportedly also be exploited to disclose the full path to the user's profile via errors thrown in installed extensions.
The weakness has been confirmed in version 1.5.0.3. Other versions may also be affected.
Solution:
Disable JavaScript support…"

:(