Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-23 Thread Eric Dorland
tags 340283 - security thanks * Florian Weimer ([EMAIL PROTECTED]) wrote: > severity 340283 grave > thanks > > * Mike Hommey: > > > severity 340283 important > > thanks > > > > Until it is proven that the crash can lead to an exploit, it's not > > critical. > > A crash which can be triggered ju

Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Florian Weimer
* Mike Hommey: > If you think a bare crash needs severity grave, then please go ahead > and raise severity of Most of these bugs are not exploitable, i.e. an attacker cannot use them to deliberately cause data loss. > #270822, Not reproducible, non-standard configuration, not exploitable. > #

Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Mike Hommey
severity 340283 important thanks On Tue, Nov 22, 2005 at 01:46:16PM +0100, Florian Weimer <[EMAIL PROTECTED]> wrote: > severity 340283 grave > thanks > > * Mike Hommey: > > > severity 340283 important > > thanks > > > > Until it is proven that the crash can lead to an exploit, it's not > > crit

Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Florian Weimer
severity 340283 grave thanks * Mike Hommey: > severity 340283 important > thanks > > Until it is proven that the crash can lead to an exploit, it's not > critical. A crash which can be triggered just by visiting some web site *is* an exploit. Furthermore, according to the release criteria for e

Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Mike Hommey
severity 340283 important thanks Until it is proven that the crash can lead to an exploit, it's not critical. Mike On Tue, Nov 22, 2005 at 12:33:33PM +0100, Florian Weimer <[EMAIL PROTECTED]> wrote: > Package: mozilla-firefox > Version: 1.0.7-1 > Severity: grave > Tags: security > > An exploit

Bug#340283: [CVE-2005-1790] DoS against Mozilla-based browsers

2005-11-22 Thread Florian Weimer
Package: mozilla-firefox Version: 1.0.7-1 Severity: grave Tags: security An exploit for CVE-2005-1790, a bug originally classified as IE-only, causes Mozilla-based browsers to crash. See the proof of concept exploit (for IE) at: The