Multiple Web Browser Image-Based Information Leak

Source: HISPASEC SYSTEMS

Favorite

Free registration required

Multiple web browsers, including Mozilla Firefox 2.0.0.11, Opera 9.50 beta, Apple Safari 3.0.4 and Konqueror 3.5.8, contain unsafe image loading code. Exploiting the code leads to echoing a small, random, heap memory area on the screen - as image data. In case of the web browsers with fully implemented HTML5 tag functionality (Firefox and Opera), the image data can be collected, and sent to a remote server using a simple JavaScript script.
Format:PDF Size:184.20
Date:May 2008