[Secure-testing-team] Re: CVE-2006-6954 Iceweasel

Eric Dorland eric at kuroneko.ca
Fri Feb 9 06:35:17 UTC 2007


* Alex de Oliveira Silva (enerv at host.sk) wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Hi Eric.
> 
> This CVE is for Flock beta 1 0.7 but I have tested the "proof of
> concept" in Iceweasel 2.0.0.1 and it crash.
> I don't know if is a really bug.
> Could you please test it and send report for me and
> secure-testing-team at lists.alioth.debian.org ?

It locks up my browser hard, but it doesn't crash it. 
 
> Note:
> Prof of concept attached in email.
> 
> Thanks in advanced.
> 
> regards,
> - --
>    .''`.  
>   : :' :    Alex de Oliveira Silva | enerv
>   `. `'     www.enerv.net
>     `-
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.6 (GNU/Linux)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
> 
> iD8DBQFFvzklarbczl+z12gRAgQpAJ9tKLFaw7ove9MRqgtvtC5ywSjqUQCgw1ku
> QFavzMslTr6/czAACFmoty8=
> =U2L+
> -----END PGP SIGNATURE-----
> 

>               Credit's to n00b..Round {2} of the marquee bug's...
> 


-- 
Eric Dorland <eric at kuroneko.ca>
ICQ: #61138586, Jabber: hooty at jabber.com
1024D/16D970C6 097C 4861 9934 27A0 8E1C  2B0A 61E9 8ECF 16D9 70C6

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20070209/4be98be1/attachment.pgp


More information about the Secure-testing-team mailing list