Discovered by Ahmed Ghandour <[email protected]>. Posted to Bugtraq on november 24, 1999.
Vulnerable:
Netscape Communicator 4.61
-
Caldera OpenLinux Desktop 2.3
-
Caldera OpenLinux eBuilder 3.0
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows NT 4.0
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.1 sparc
-
Redhat Linux 6.1 i386
-
Redhat Linux 6.1 alpha
-
Redhat Linux 6.0 sparc
-
Redhat Linux 6.0 alpha
-
Redhat Linux 6.0
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eServer 2.3
-
SuSE Linux 7.0
Netscape Communicator 4.51
-
Caldera OpenLinux Desktop 2.3
-
Caldera OpenLinux eBuilder 3.0
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows NT 4.0
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.1 sparc
-
Redhat Linux 6.1 i386
-
Redhat Linux 6.1 alpha
-
Redhat Linux 6.0 sparc
-
Redhat Linux 6.0 alpha
-
Redhat Linux 6.0
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eServer 2.3
-
SuSE Linux 7.0
Netscape Communicator 4.7
-
Caldera OpenLinux Desktop 2.3
-
Caldera OpenLinux eBuilder 3.0
-
FreeBSD FreeBSD 4.5
-
FreeBSD FreeBSD 4.4
-
FreeBSD FreeBSD 4.3
-
FreeBSD FreeBSD 4.2
-
FreeBSD FreeBSD 4.1.1
-
FreeBSD FreeBSD 4.1
-
FreeBSD FreeBSD 4.0
-
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows 2000 Professional SP1
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows NT 4.0 SP6a
-
Microsoft Windows NT 4.0 SP6
-
Microsoft Windows NT 4.0 SP5
-
Microsoft Windows NT 4.0 SP4
-
Microsoft Windows NT 4.0 SP3
-
Microsoft Windows NT 4.0 SP2
-
Microsoft Windows NT 4.0 SP1
-
Microsoft Windows NT 4.0
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.1 sparc
-
Redhat Linux 6.1 i386
-
Redhat Linux 6.1 alpha
-
Redhat Linux 6.0 sparc
-
Redhat Linux 6.0 alpha
-
Redhat Linux 6.0
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eServer 2.3
-
SuSE Linux 7.0
Netscape Communicator 4.6
-
Caldera OpenLinux Desktop 2.3
-
Caldera OpenLinux eBuilder 3.0
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows NT 4.0
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.1 sparc
-
Redhat Linux 6.1 i386
-
Redhat Linux 6.1 alpha
-
Redhat Linux 6.0 sparc
-
Redhat Linux 6.0 alpha
-
Redhat Linux 6.0
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eServer 2.3
-
SuSE Linux 7.0
Netscape Communicator 4.5
-
Caldera OpenLinux Desktop 2.3
-
Caldera OpenLinux eBuilder 3.0
-
Mandriva Linux Mandrake 7.1
-
Mandriva Linux Mandrake 7.0
-
Mandriva Linux Mandrake 6.1
-
Mandriva Linux Mandrake 6.0
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows NT 4.0
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.1 sparc
-
Redhat Linux 6.1 i386
-
Redhat Linux 6.1 alpha
-
Redhat Linux 6.0 sparc
-
Redhat Linux 6.0 alpha
-
Redhat Linux 6.0
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eServer 2.3
-
SuSE Linux 7.0
Netscape Communicator 4.0
-
Caldera OpenLinux Desktop 2.3
-
Caldera OpenLinux eBuilder 3.0
-
Mandriva Linux Mandrake 7.1
-
Mandriva Linux Mandrake 7.0
-
Mandriva Linux Mandrake 6.1
-
Mandriva Linux Mandrake 6.0
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows NT 4.0
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.1 sparc
-
Redhat Linux 6.1 i386
-
Redhat Linux 6.1 alpha
-
Redhat Linux 6.0 sparc
-
Redhat Linux 6.0 alpha
-
Redhat Linux 6.0
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eServer 2.3
-
SuSE Linux 7.0
Netscape Communicator 4.07
-
Caldera OpenLinux Desktop 2.3
-
Caldera OpenLinux eBuilder 3.0
-
Mandriva Linux Mandrake 7.1
-
Mandriva Linux Mandrake 7.0
-
Mandriva Linux Mandrake 6.1
-
Mandriva Linux Mandrake 6.0
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows NT 4.0
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.1 sparc
-
Redhat Linux 6.1 i386
-
Redhat Linux 6.1 alpha
-
Redhat Linux 6.0 sparc
-
Redhat Linux 6.0 alpha
-
Redhat Linux 6.0
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eServer 2.3
-
SuSE Linux 7.0
Netscape Communicator 4.06
-
Caldera OpenLinux Desktop 2.3
-
Caldera OpenLinux eBuilder 3.0
-
Mandriva Linux Mandrake 7.1
-
Mandriva Linux Mandrake 7.0
-
Mandriva Linux Mandrake 6.1
-
Mandriva Linux Mandrake 6.0
-
Microsoft Windows 2000 Professional
-
Microsoft Windows 95
-
Microsoft Windows 98
-
Microsoft Windows NT 4.0
-
Redhat Linux 6.2 sparc
-
Redhat Linux 6.2 i386
-
Redhat Linux 6.2 alpha
-
Redhat Linux 6.1 sparc
-
Redhat Linux 6.1 i386
-
Redhat Linux 6.1 alpha
-
Redhat Linux 6.0 sparc
-
Redhat Linux 6.0 alpha
-
Redhat Linux 6.0
-
Redhat Linux 5.2 sparc
-
Redhat Linux 5.2 i386
-
Redhat Linux 5.2 alpha
-
SCO eDesktop 2.4
-
SCO eServer 2.3
-
SuSE Linux 7.0
Netscape Communicator 4.x will allow javascript code in one browser window to read javascript data from another browser window, regardless of whether the two browsers are pointed to the same location or domain. This could allow a malicious webpage to open another browser pointing to another site, then record any information sent or retreived in the second browser. This could lead to credential or credit information theft.
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].