0DAY Firefox Remote Code Execution and Denial of Service Vulnerability <=1.5.0.2 iframe.contentWindow.focus()

[email protected]
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
---------------------------------------------------
Software:  
 Firefox Web Browser
Tested: 
 Linux, Windows clients' version 1.5.0.2
Result:  
 Firefox Remote Code Execution and Denial of Service
Problem:
 A handling issue exists in how Firefox handles certain Javascript in js310.dll and xpcom_core.dll
regarding iframe.contentWindow.focus().  By manipulating this feature a buffer overflow will occur.  
Proof of Concept:
 http://www.securident.com/vuln/ff.txt
Credits:
 splices(splices [dot] org)
 spiffomatic64(spiffomatic64 [dot] com)
 Securident Technologies (securident [dot] com)      
------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.