A browser flaw that affects Mozilla Browser, Mozilla Firefox, Opera, and Apple Safari has been discovered. It causes them to crash and could potentially form the basis of an exploit that would affect virtually all major browsers.
The bug has been called the Infinite Array Sort Denial Of Service Vulnerability and causes the affected browsers to execute an infinite JavaScript array sort. That operation in turn effectively causes a DoS on the browser in question and causes it to crash by exhausting stack memory.
At present there are no confirmed exploits in the wild that expand the vulnerability to execute malicious code, though that may only be a matter of time.
Independent security researcher Berend-Jan Wever is credited with discovering the flaw. Though the flaw was just disclosed on security mailing lists, Wever has been aware of the flaw for some time and like many researchers had begun his efforts with a focus on IE.
Source: Internet News

Articles RSS