It appears that SANS ISC has a summary type entry including link to related CNET TV Video (2min 9sec) too:
http://isc.sans.org/diary.php?storyid=1756
They have a lot of reference links.
- Juha-Matti
Dave Aitel <dave_at_immunityinc.com> wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Didn't you post on your weblog some stuff about Chrome: being buggy?
> It's completely believable to have a chrome: context issue in Firefox.
> I recall you said something about iterators, but I don't have a
> Mozilla developer account so I can't look at the diff.
>
> Are the slides/full PoC available publicly?
> - -dave
>
> Thor Larholm wrote:
> > Their PoC, both the one in their slides and the full PoC, is
> > nothing more than an out-of-memory crash, of which Firefox already
> > has plenty. They were still struggling to write a working exploit
> > days after the presentation, even though they claimed to have just
> > that during the presentation.
> >
> > Long story short, the bug is just a bug - not a vulnerability.
> >
> >
> > Regards Thor Larholm
_______________________________________________
Dailydave mailing list
Dailydave_at_lists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave
Received on Oct 03 2006