So yesterday we were all atwitter over this “impossible to patch” JavaScript flaw in Firefox. Today is another – apparently more secure – day as Mischa Spiegelmock, one of the researchers who unearthed the problem, is backtracking on his claims, whistling nonchalantly and slowly walking backwards with his hands in his pockets. What was initially thought to be a zero-day exploit now could just make your browser crash. “As part of our talk we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution,” Spiegelmock states. “However, I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven’t used it to take over anyone else’s computer and execute arbitrary code.” Details here. Edit, 10:39 a.m. Oct. 4: Now the chumps say “Kidding! It’s a joke!”. Punks. Via The Register
Firefox flaw not so bad after all
Opinion
Oct 4, 20061 min





