Netscape Communicator EMBED Buffer Overflow Vulnerability
BID:618
Info
Netscape Communicator EMBED Buffer Overflow Vulnerability
| Bugtraq ID: | 618 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 02 1999 12:00AM |
| Updated: | Sep 02 1999 12:00AM |
| Credit: | Posted to Bugtraq on September 2, 1999 by DEF CON ZERO WINDOW <[email protected]>. |
| Vulnerable: |
Netscape Communicator 4.61 Netscape Communicator 4.51 Netscape Communicator 4.6 Netscape Communicator 4.5 Netscape Communicator 4.06 |
| Not Vulnerable: |
Netscape Communicator 4.7 |
Discussion
Exploit / POC
Netscape Communicator EMBED Buffer Overflow Vulnerability
These exploits were designed for Windows 98. On windows NT they will cause Netscape to crash.
NOTE: Many people have reported that the following exploits only cause Netscape 4.0 - 4.61 under Win98 to crash, but do not execute any other code.
This one will execute welcome.exe:
http://www.ugtop.com/defcon0/hc/nc4x_ex/nc4x_ex.cgi
This one will execute notepad.exe:
http://www.ugtop.com/defcon0/hc/nc4x_ex/nc4x_ex2.cgi
These exploits were designed for Windows 98. On windows NT they will cause Netscape to crash.
NOTE: Many people have reported that the following exploits only cause Netscape 4.0 - 4.61 under Win98 to crash, but do not execute any other code.
This one will execute welcome.exe:
http://www.ugtop.com/defcon0/hc/nc4x_ex/nc4x_ex.cgi
This one will execute notepad.exe:
http://www.ugtop.com/defcon0/hc/nc4x_ex/nc4x_ex2.cgi
Solution / Fix
Netscape Communicator EMBED Buffer Overflow Vulnerability
Solution:
Testing of Netscape Communicator 4.7 indicates that it is not subject to this vulnerability.
Solution:
Testing of Netscape Communicator 4.7 indicates that it is not subject to this vulnerability.
References
Netscape Communicator EMBED Buffer Overflow Vulnerability
References:
References: