[39875] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: Netscape bug update

daemon@ATHENA.MIT.EDU (David J. Bianco)
Fri Sep 22 08:31:46 1995

From: "David J. Bianco" <bianco@itribe.net>
Date: Fri, 22 Sep 1995 08:29:53 -0400
In-Reply-To: Ray Cromwell <rjc@clark.net>
        "Netscape bug update" (Sep 22,  2:26)
To: Ray Cromwell <rjc@clark.net>, cypherpunks@toad.com

On Sep 22,  2:26, Ray Cromwell sent the following to the NSA's mail
archives:
> Subject: Netscape bug update
||
||   I just verified in GDB using a stack trace that the Netscape overflow
|| bug I mentioned is indeed a static stack buffer overflow. It trashes
|| the stack.
||
||   What this means is that in theory, it is possible to get a simple
|| URL, if clicked on, to execute some code on someone's browser.
||
||   Now the hard work begins...
||

This is a new feature of Netscape 2.0, part of the Java package
I believe... ;-)

--
==========================================================================
David J. Bianco			| Web Wonders, Online Oddities, Cool Stuff
iTribe, Inc.			| Phone: (804) 446-9060 Fax: (804) 446-9061
Suite 1700, World Trade Center	| email: <bianco@itribe.net>
Norfolk, VA 23510		| URL  : http://www.itribe.net/~bianco/

home help back first fref pref prev next nref lref last post