23 Explorer bug crawls up on Firefox

Posted: Nov 29, 2005, under Software, Security. Updated: Nov 30, 2005. Add a comment!

I was reading about the Internet Explorer JavaScript Window() Remote Code Execution advisory published by CT, and, naturally, I tried the proof-of-concept.

Tried it in Explorer on a Win2K with all the latest patches. It worked quite well, both versions of the p-o-c actually (Win2K and XP).

Then a colleague suggested we try it in Firefox. I thought the idea was crazy, since I’d read the advisory and it seemed very Explorer-specific.

Nevertheless, we tried it, both in 1.0.7 and 1.5 RC3. It managed to freeze them both, with the CPU going to 100%.

Now that’s what I call a bug.

Update: The bug is tracked by the Firefox developers as 317334 and discussed here.