Gentoo Archives: gentoo-hardened

From: atoth@××××××××××.hu
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Firefox+PaX+amazon.com
Date: Sun, 04 Nov 2007 06:56:25
Message-Id: 33569.138.26.140.45.1194159267.squirrel@atoth.sote.hu
1 FYI:
2 I've bumped Firefox to 2.0.0.8 a few hours ago. I recompiled all plugins
3 and the noscript extension. Visiting amazon.com now results in a PaX
4 execution attempt. If I filter amazon using noscript and adblock, it loads
5 fine.
6
7 I guess it must be some flash content. It doesn't bother me enough to
8 trace back the problem.
9
10 This example shows, that PaX should be running on ordinary machines, not
11 just servers. Stack execution is a real life threat.
12
13 Regards,
14 Dw.
15 --
16 dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962
17 Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
18
19 --
20 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Firefox+PaX+amazon.com pageexec@××××××××.hu