Quantcast
Channel: Files from Michal Zalewski ≈ Packet Storm
Viewing all articles
Browse latest Browse all 25

Mozilla Firefox Secret Leak

$
0
0
The recent release of Firefox 32 fixes another interesting image parsing issue found by afl. Following a refactoring of memory management code, the past few versions of the browser ended up using uninitialized memory for certain types of truncated images, which is easily measurable with a simple + toDataURL() harness that examines all the fuzzer-generated test cases. Depending on a variety of factors, problems like that may leak secrets across web origins, or more prosaically, may help attackers bypass security measures such as ASLR. This code is a proof of concept for versions prior to 32.

Viewing all articles
Browse latest Browse all 25

Trending Articles