[24767] in bugtraq

home help back first fref pref prev next nref lref last post

[Bug 131761] Buffer Overflow in Geck/Netscape 5.0/6.0?

daemon@ATHENA.MIT.EDU (Jonathan A. Zdziarski)
Thu Mar 21 02:09:22 2002

From: "Jonathan A. Zdziarski" <jonathan@networkdweebs.com>
To: <bugtraq@securityfocus.com>
Date: Tue, 19 Mar 2002 09:01:25 -0500
Message-ID: <000d01c1cf4e$8f7b3660$0200000a@shamah>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
In-Reply-To: <200203190700.20975@mbjr.dyndns.org>

It looks like this bug was fixed in 0.9.6, and hasn't made its way into
the Netscape build yet, and RedHat appears to still be distributing the
older browser.  The 0.9.6 fix:

http://bugzilla.mozilla.org/show_bug.cgi?id=100595

Netscape does not feel that this is a security hole, as the junk being
outputted is only pointing to a freed memory buffer.  The worse that
they feel could happen is that it could cause the browser to crash and
possibly spill some contents from the freed memory, but it should not be
possible to execute any code by placing data in the right place.

Future versions of Netscape should automatically be patched as soon as
they build with a version of Mozilla >=0.9.6




home help back first fref pref prev next nref lref last post