|
|
| |
| A vulnerability in Netscape browser allows remote attackers to corrupt the memory of the browser by sending it malformed HTML content. |
| |
Credit:
The information has been provided by Juha-Matti Laurio.
|
| |
Vulnerable Systems:
* Netscape Browser version 8.1 in Windows 2000 SP4 fully patched
Immune Systems:
* Firefox version 1.5.0.6
When visiting the test link http://lcamtuf.coredump.cx/ffoxdie.html (included to the original vulnerability report related to Firefox) browser crashed immediately generating Application Error. No user interaction was needed.
Solution status:
No updated version available from the vendor at the time of reporting.
Workarounds:
The following working workaround has been tested: Disable JavaScript support from Tools / Options... / Site Controls.
Timeline:
18-Aug-2006 - Vulnerability confirmed in Netscape
19-Aug-2006 - Vendor was contacted
19-Aug-2006 - Security companies and several CERT units contacted
|
|
|
|
|
|
|
|