<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: milw0rm 9158 &#8220;stack overflow&#8221; crash not exploitable (CVE-2009-2479)</title>
	<atom:link href="http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/</link>
	<description></description>
	<lastBuildDate>Thu, 19 Nov 2009 15:36:11 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Adam</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106947</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Sat, 15 Aug 2009 14:43:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106947</guid>
		<description>http://milw0rm.com/exploits/9247

The above link contains the full POC code for an exploit based on Firefox 3.5

I am not happy that Mozilla have brushed this one off as it is a *serious* vulnerability and I a not aware of any patches being released.</description>
		<content:encoded><![CDATA[<p><a href="http://milw0rm.com/exploits/9247" rel="nofollow">http://milw0rm.com/exploits/9247</a></p>
<p>The above link contains the full POC code for an exploit based on Firefox 3.5</p>
<p>I am not happy that Mozilla have brushed this one off as it is a *serious* vulnerability and I a not aware of any patches being released.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mercohaulic</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106064</link>
		<dc:creator>mercohaulic</dc:creator>
		<pubDate>Thu, 23 Jul 2009 02:23:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106064</guid>
		<description>Anyone know about this:
http://www.securityfocus.com/advisories/17380

States that Mozilla Firefox has multiple vulnerabilities not found in versions 3.5 and 3.0.12. 
So Im guessing that the others are and we should patch them to either of these versions?</description>
		<content:encoded><![CDATA[<p>Anyone know about this:<br />
<a href="http://www.securityfocus.com/advisories/17380" rel="nofollow">http://www.securityfocus.com/advisories/17380</a></p>
<p>States that Mozilla Firefox has multiple vulnerabilities not found in versions 3.5 and 3.0.12.<br />
So Im guessing that the others are and we should patch them to either of these versions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cat</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106057</link>
		<dc:creator>cat</dc:creator>
		<pubDate>Tue, 21 Jul 2009 06:11:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106057</guid>
		<description>I&#039;ve read this post and the update to Security First. I&#039;ve also read this article: http://www.theregister.co.uk/2009/07/20/firefox_flaw/

This paragraph concerns me:

&quot;Reports by security researchers at the Internet Storm Centre (here) and elsewhere suggest the flaw might lend itself to code injection. Worse still, proof of concept code has been published; a development that normally reduces the odds on whether hacking attacks might follow.&quot;

To me (a lay person) this reads that it is a vulnerability and it is only a matter of time before this could become a security risk. Correct me if my interpretation is wrong. I would hope that Mozilla issues a priority patch asap in view of this. It is the swift correcting of actual and potential security issues that makes FF my preferred browser.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve read this post and the update to Security First. I&#8217;ve also read this article: <a href="http://www.theregister.co.uk/2009/07/20/firefox_flaw/" rel="nofollow">http://www.theregister.co.uk/2009/07/20/firefox_flaw/</a></p>
<p>This paragraph concerns me:</p>
<p>&#8220;Reports by security researchers at the Internet Storm Centre (here) and elsewhere suggest the flaw might lend itself to code injection. Worse still, proof of concept code has been published; a development that normally reduces the odds on whether hacking attacks might follow.&#8221;</p>
<p>To me (a lay person) this reads that it is a vulnerability and it is only a matter of time before this could become a security risk. Correct me if my interpretation is wrong. I would hope that Mozilla issues a priority patch asap in view of this. It is the swift correcting of actual and potential security issues that makes FF my preferred browser.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Lefevre</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106049</link>
		<dc:creator>Michael Lefevre</dc:creator>
		<pubDate>Mon, 20 Jul 2009 15:29:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106049</guid>
		<description>@Freezer: I&#039;m sure they are not saying it isn&#039;t malicious instead of fixing it. They are saying it isn&#039;t malicious as well as fixing it (but I guess that will happen in one of the future regular updates, rather than having a special release just to fix this).

It&#039;s an unfortunate fact that there are dozens of ways for web pages to crash or hang Firefox. The same applies to all other browsers. Which is why IE, Chrome, and in future Firefox, are putting different pages in different processes, so you only lose the one that has crashed.</description>
		<content:encoded><![CDATA[<p>@Freezer: I&#8217;m sure they are not saying it isn&#8217;t malicious instead of fixing it. They are saying it isn&#8217;t malicious as well as fixing it (but I guess that will happen in one of the future regular updates, rather than having a special release just to fix this).</p>
<p>It&#8217;s an unfortunate fact that there are dozens of ways for web pages to crash or hang Firefox. The same applies to all other browsers. Which is why IE, Chrome, and in future Firefox, are putting different pages in different processes, so you only lose the one that has crashed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Transcontinental</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106046</link>
		<dc:creator>Transcontinental</dc:creator>
		<pubDate>Mon, 20 Jul 2009 13:27:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106046</guid>
		<description>I&#039;m not saying this is, but I assume it could be now or it may be one day: as the browsers&#039; war is becoming tougher, as Firefox is gaining more and more users as popularity, assertions of insecurity will rise based on the slightest cough. This is still our world: do it, should it be by all means.
Firefox has always been and remains the leader in terms of security and privacy, patches are issued quickly, but let not the fact of transparency blind us to an insecurity which would not be the case of other browsers&#039; because of opacity in publication of flaws.
I remain puzzled to observe how some bloggers shoot - or try to shoot - a browser on the first opportunity they have. Future is that of fairness and fraternity, also because common problems concern all, browsers included.
I remain A Firefox user, not only for the browser I experiment 16 hours a day as secure, fast, stable, but also as an admirer of the Mozilla philosophy.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not saying this is, but I assume it could be now or it may be one day: as the browsers&#8217; war is becoming tougher, as Firefox is gaining more and more users as popularity, assertions of insecurity will rise based on the slightest cough. This is still our world: do it, should it be by all means.<br />
Firefox has always been and remains the leader in terms of security and privacy, patches are issued quickly, but let not the fact of transparency blind us to an insecurity which would not be the case of other browsers&#8217; because of opacity in publication of flaws.<br />
I remain puzzled to observe how some bloggers shoot &#8211; or try to shoot &#8211; a browser on the first opportunity they have. Future is that of fairness and fraternity, also because common problems concern all, browsers included.<br />
I remain A Firefox user, not only for the browser I experiment 16 hours a day as secure, fast, stable, but also as an admirer of the Mozilla philosophy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry Seltzer</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106045</link>
		<dc:creator>Larry Seltzer</dc:creator>
		<pubDate>Mon, 20 Jul 2009 13:22:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106045</guid>
		<description>I&#039;ve followed up on this on Bugzilla (https://bugzilla.mozilla.org/show_bug.cgi?id=504342)</description>
		<content:encoded><![CDATA[<p>I&#8217;ve followed up on this on Bugzilla (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=504342)" rel="nofollow">https://bugzilla.mozilla.org/show_bug.cgi?id=504342)</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Veditz</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106040</link>
		<dc:creator>Daniel Veditz</dc:creator>
		<pubDate>Mon, 20 Jul 2009 06:52:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106040</guid>
		<description>We&#039;re saying it isn&#039;t malicious because press reports are spreading incorrect information and scaring people.</description>
		<content:encoded><![CDATA[<p>We&#8217;re saying it isn&#8217;t malicious because press reports are spreading incorrect information and scaring people.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Freezer</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106039</link>
		<dc:creator>Freezer</dc:creator>
		<pubDate>Mon, 20 Jul 2009 06:43:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106039</guid>
		<description>Oh please! It doesn&#039;t convince me. I&#039;m a layman and a diehard firefox user and i would expect you to fix it instead of saying it isn&#039;t malicious. Please fix it because i like FF so much.</description>
		<content:encoded><![CDATA[<p>Oh please! It doesn&#8217;t convince me. I&#8217;m a layman and a diehard firefox user and i would expect you to fix it instead of saying it isn&#8217;t malicious. Please fix it because i like FF so much.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: buzza</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106038</link>
		<dc:creator>buzza</dc:creator>
		<pubDate>Mon, 20 Jul 2009 04:36:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106038</guid>
		<description>yes nice to know that mozilla is kind enough to test firefox ON linux (NOT). Yet another reason why i can&#039;t wait for chrome to become better.</description>
		<content:encoded><![CDATA[<p>yes nice to know that mozilla is kind enough to test firefox ON linux (NOT). Yet another reason why i can&#8217;t wait for chrome to become better.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cat</title>
		<link>http://blog.mozilla.com/security/2009/07/19/milw0rm-9158-stack-overflow-crash-not-exploitable-cve-2009-2479/comment-page-1/#comment-106037</link>
		<dc:creator>cat</dc:creator>
		<pubDate>Mon, 20 Jul 2009 03:48:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=120#comment-106037</guid>
		<description>This post is about this &gt; http://www.malwarebytes.org/forums/index.php?showtopic=19644 right? 

Could you please clarify if it is safe to enable JavaScript in FF 3.5.1? I read your post and decided it was, until I read the edit re FF crashing on PoC on Windows and now I&#039;m confused. (The edit and the details of Larry Seltzer&#039;s comment go way above my head, so I just want to be sure). 

Thanks. :)</description>
		<content:encoded><![CDATA[<p>This post is about this &gt; <a href="http://www.malwarebytes.org/forums/index.php?showtopic=19644" rel="nofollow">http://www.malwarebytes.org/forums/index.php?showtopic=19644</a> right? </p>
<p>Could you please clarify if it is safe to enable JavaScript in FF 3.5.1? I read your post and decided it was, until I read the edit re FF crashing on PoC on Windows and now I&#8217;m confused. (The edit and the details of Larry Seltzer&#8217;s comment go way above my head, so I just want to be sure). </p>
<p>Thanks. <img src='http://blog.mozilla.com/security/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
