Sploitus

Exploit for Mozilla Firefox document.write and DOM insertion memory corruption

saint · 2010-11-04

Exploit Code

MARKDOWN36 lines
## https://sploitus.com/exploit?id=SAINT:5304BC5AECD536DD889896AA44B31199
Added: 11/04/2010  
CVE: CVE-2010-3765  
BID: 44425  
OSVDB: 68905  


### Background

Firefox is a freely available web browser for multiple platforms including Windows, Linux, and Mac OS. 

### Problem

A memory corruption vulnerability allows command execution when a user loads a specially crafted web page containing DOM insertions interspersed with calls to the document.write function. 

### Resolution

Upgrade to Firefox 3.5.15 or 3.6.12 or higher. 

### References

http://www.mozilla.org/security/announce/2010/mfsa2010-73.html   
http://secunia.com/advisories/41957/   


### Limitations

Exploit works on Firefox 3.6.11 and requires the user to load the exploit page in Firefox. 

It may take some time to establish the shell session. 

The exploit works best when the target platform has more than 1G memory. 

### Platforms

Windows