Thursday, October 20, 2005

Mozilla Firefox IDN Host Buffer Overflow

An attacker could remotely execute code on a vulnerable system because of an exploitable Firefox buffer overflow vulnerability. This vulnerability can be exploited by giving Firefox a very long url made up of dashes. Firefox is vulnerable due to the way it handles the International Domain Name (IDN) feature for web pages not using the standard Latin alphabet characters.