Mozilla Firefox/SeaMonkey UTF-8 Stack-Based Buffer Overflow Vulnerability

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

The following proof of concept is available to members of the Immunity Partners Program:

https://www.immunityinc.com/downloads/immpartners/firefox_utf8.tar.gz

The following exploit code is available to members of the Immunity Partners Program:

https://www.immunityinc.com/downloads/immpartners/firefox_utf8-r2.tar.gz

The following exploit is available:


 

Privacy Statement
Copyright 2010, SecurityFocus