---------------------------------------------------------------------- Secunia is pleased to announce the release of the annual Secunia report for 2008. Highlights from the 2008 report: * Vulnerability Research * Software Inspection Results * Secunia Research Highlights * Secunia Advisory Statistics Request the full 2008 Report here: http://secunia.com/advisories/try_vi/request_2008_report/ Stay Secure, Secunia ---------------------------------------------------------------------- TITLE: Mozilla Firefox XSLT Processing Invalid Evaluation Context Weakness SECUNIA ADVISORY ID: SA34471 VERIFY ADVISORY: http://secunia.com/advisories/34471/ DESCRIPTION: A weakness has been discovered in Mozilla Firefox, which can be exploited by malicious people to cause a DoS (Denial of Service). The weakness is caused due to the improper handling of errors encountered when transforming an XML document. This can be exploited to trigger the handling of a temporary, corrupted stack variable as an evaluation context object via specially crafted XSLT code. Successful exploitation crashes the browser. However, even though code execution has not been proven, it cannot be completely ruled out. NOTE: Secunia normally does not classify a browser crash as a vulnerability nor issue an advisory about it. However, the potential impact of this issue may be more severe than currently believed. The weakness is confirmed in version 3.0.7 for Windows. Other versions may also be affected. SOLUTION: Do not browse untrusted websites or follow untrusted links. PROVIDED AND/OR DISCOVERED BY: k'sOSe ORIGINAL ADVISORY: http://milw0rm.com/exploits/8285 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------