Advisory describing vulnerability released for bug in Firefox 2.0.0.11 and Opera 9.5 beta-users should ensure they have updated
February 18, 2008
The advisory, regarding an image file flaw, was released by ‘gynvael coldwind’, on Vexillium on the 16th of February. The Firefox patch to correct this and other security issues was released on the 7th of February.
The vulnerability is in the way the BMP files are handled. The code allows information from the heap-various data including users “favorites” and history, and other information-to be leaked. An attacker can send this information to a remote website by using tag and JavaScript. It is also possible to cause Remote Denial of Service.


Comments
Got something to say?
Visited 214 times, 1 so far today