vendor:
Firefox
by:
none
8,5
CVSS
HIGH
Denial of Service
none
CWE
Product Name: Firefox
Affected Version From: Firefox 3.0.10 (Windows)
Affected Version To: All Firefox versions supporting the KEYGEN tag.
Patch Exists: No
Related CWE: none provided
CPE: none
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Firefox Denial of Service (KEYGEN)
This bug is a simple design bug that results in an endless loop (and interesting memory leaks). Once upon a time Netscape thought it would be a great idea to add the keygen tag (<keygen>) as a feature to their Browser. The keygen tag offers a simple way of automatically generating key material using various algorithms. For instance it is possible to generate RSA, DSA and EC key material.
Mitigation:
There is no workaround.