SAN DIEGO, Calif.--The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon.An attacker could commandeer a computer running the browser simply by crafting a Web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference here.
This entry is pointing to ZDNet news as well.
CERT organisation US-CERT has assigned a specific Current Activity alert too:
http://www.us-cert.gov/current/current_ ... tml#ff0day
and vulnerability advisory BID20282 (i.e. Bugtraq ID) has been assigned:
http://www.securityfocus.com/bid/20282/info
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; fi; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7



