[24744] in bugtraq
RE: Buffer Overflow in Geck/Netscape 5.0/6.0?
daemon@ATHENA.MIT.EDU (Pauls, Nicole)
Tue Mar 19 18:46:01 2002
content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Date: Mon, 18 Mar 2002 09:34:07 -0800
Message-ID: <4BCD64ABC2F0674081427118425616E4389B0D@post.corp.trigeo.com>
From: "Pauls, Nicole" <npauls@trigeo.com>
To: "Jonathan A. Zdziarski" <jonathan@networkdweebs.com>,
<bugtraq@securityfocus.com>
Content-Transfer-Encoding: 8bit
The best way to handle this is to report a bug. It will be handled by the
Mozilla engineers.
http://bugzilla.mozilla.org
-----Original Message-----
From: Jonathan A. Zdziarski [mailto:jonathan@networkdweebs.com]
Sent: Saturday, March 16, 2002 12:19 PM
To: bugtraq@securityfocus.com
Subject: Buffer Overflow in Geck/Netscape 5.0/6.0?
We've been investigating a problem that seems to occur whenever Netscape
6.0 or Mozilla Gecko 5.0 receive Multipart/Mixed information, that
appears to be a buffer overflow or in the code. At the very least,
there appears to be a condition allowing a partial memory dump to the
screen.