MozTW 討論區 https://forum.moztw.org/ |
|
Firefox 3.6的「零時差漏洞」:至今未被修 https://forum.moztw.org/viewtopic.php?f=2&t=29544 |
第 1 頁 (共 1 頁) |
發表人: | feistybird [ 2010-02-21, 16:59 ] |
文章主題 : | Firefox 3.6的「零時差漏洞」:至今未被修 |
俄羅斯安全公司Intevydis已經發現了基於Windows的Firefox 3.6上的一個安全漏洞,該漏洞可以讓駭客遠程控制被攻擊的個人電腦。發現該漏洞的程序員Evgeny Legerov稱該漏洞利用的是「緩衝區溢出」,而且在Windows XP(SP3)和Vista上可被穩定利用。 儘管這一問題在二月初就被公佈,但是這個問題到Firefox 3.6發佈之日也未被解決,Mozilla Firefox似乎沒有對此問題引起足夠的重視。 引言回覆: While the post dates back to the beginning of February, the hole is likely to remain open since no updates have been released for Firefox 3.6 so far. Secunia rates the problem as critical, but hasn't provided any further information in its advisories and the Mozilla Foundation has become aware of the problem, but has yet to release an official statement. Whether the exploit has already been widely circulated or used on a large scale remains unknown. However, according to the analysis on the Extraexploit blog, a significant increase in the number of Firefox 3.6 crashes was noted on the 12th and 13th of February. It is unclear whether the crashes were connected to the exploit being tested. The pages causing the highest number of crashes are listed in Mozilla's crash reports.
|
發表人: | BobChao [ 2010-02-24, 00:13 ] |
文章主題 : | Re: Firefox 3.6的「零時差漏洞」:至今未被修 |
http://secunia.com/advisories/38608/ 有些人回報無法重製,Mozilla 也表示無法證實這個問題。我想找那個公司出的攻擊程式來攻擊自己測試,但沒找著,有連結的麻煩順便提供一下。 |
發表人: | gandalf_Zoro [ 2010-02-24, 10:15 ] |
文章主題 : | Re: Firefox 3.6的「零時差漏洞」:至今未被修 |
這一個嗎, 好像是收費軟件 http://www.intevydis.com/vulndisco.shtml |
第 1 頁 (共 1 頁) | 所有顯示的時間為 UTC + 8 小時 |
Powered by phpBB® Forum Software © phpBB Group https://www.phpbb.com/ |