漏洞信息详情
Netscape Navigator ‘about:’Domain信息泄露漏洞
- CNNVD编号:CNNVD-200108-023
- 危害等级: 高危
- CVE编号:
CVE-2001-0596
- 漏洞类型:
其他
- 发布时间:
2001-08-02
- 威胁类型:
远程
- 更新时间:
2005-08-02
- 厂 商:
netscape - 漏洞来源:
Discovered and pos… -
漏洞简介
Netscape Communicator 4.77之前的版本存在漏洞。远程攻击者借助其注释包含Javascript的GIF图像执行任意Javascript。
漏洞公告
The following patches have been released which rectify this issue:
Netscape Navigator 4.0.8
-
Conectiva 4.0 i386 netscape-navigator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/netscape-navigator-4.77-1
cl.i386.rpm -
Conectiva 4.1 i386 netscape-navigator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/netscape-navigator-4.77-1
cl.i386.rpm -
Conectiva 4.2 i386 netscape-navigator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/netscape-navigator-4.77-1
cl.i386.rpm -
Conectiva 5.0 i386 netscape-navigator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/netscape-navigator-4.77-1
cl.i386.rpm -
Conectiva 5.1 i386 netscape-navigator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/netscape-navigator-4.77-1
cl.i386.rpm -
Conectiva 6.0 i386 netscape-navigator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/netscape-navigator-4.77-1
cl.i386.rpm -
Conectiva graficas i386 netscape-navigator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/graficas/i386/netscape
-navigator-4.77-1cl.i386.rpm -
Immunix 6.2 i386 netscape-navigator-4.77-0.6.2_StackGuard.i386.rpm
http://www.securityfocus.com/external/
http://immunix.org/ImmunixOS/6.2
/updates/RPMS/netscape-navigator-4.77-0.6.2_StackGuard.i386.rpm -
Immunix 7.0 i386 netscape-navigator-4.77-1_imnx.i386.rpm
http://www.securityfocus.com/external/
http://immunix.org/ImmunixOS/7.0
/updates/RPMS/netscape-navigator-4.77-1_imnx.i386.rpm -
Red Hat Inc. 6.2 alpha netscape-navigator-4.77-0.6.2.alpha.rpm
http://www.securityfocus.com/external/ftp://updates.redhat.com/6.2/en/
os/alpha/netscape-navigator-4.77-0.6.2.alpha.rpm -
Red Hat Inc. 6.2 i386 netscape-navigator-4.77-0.6.2.i386.rpm
http://www.securityfocus.com/external/ftp://updates.redhat.com/6.2/en/
os/i386/netscape-navigator-4.77-0.6.2.i386.rpm -
Red Hat Inc. 7.0 alpha netscape-navigator-4.77-1.alpha.rpm
http://www.securityfocus.com/external/ftp://updates.redhat.com/7.0/en/
os/alpha/netscape-navigator-4.77-1.alpha.rpm -
Red Hat Inc. 7.0 i386 netscape-navigator-4.77-1.i386.rpm
http://www.securityfocus.com/external/ftp://updates.redhat.com/7.0/en/
os/i386/netscape-navigator-4.77-1.i386.rpm -
Red Hat Inc. 7.1 i386 netscape-navigator-4.77-1.i386.rpm
ftp://updates.redhat.com/7.1/en/os/i386/netscape-navigator-4.77-1.i386
.rpm
Netscape Communicator 4.7
-
Conectiva 4.0 i386 netscape-common-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/netscape-common-4.77-1cl.
i386.rpm -
Conectiva 4.0 i386 netscape-communicator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.0/i386/netscape-communicator-4.7
7-1cl.i386.rpm -
Conectiva 4.1 i386 netscape-common-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/netscape-common-4.77-1cl.
i386.rpm -
Conectiva 4.1 i386 netscape-communicator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.1/i386/netscape-communicator-4.7
7-1cl.i386.rpm -
Conectiva 4.2 i386 netscape-common-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/netscape-common-4.77-1cl.
i386.rpm -
Conectiva 4.2 i386 netscape-communicator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/4.2/i386/netscape-communicator-4.7
7-1cl.i386.rpm -
Conectiva 5.0 i386 netscape-common-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/netscape-common-4.77-1cl.
i386.rpm -
Conectiva 5.0 i386 netscape-communicator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.0/i386/netscape-communicator-4.7
7-1cl.i386.rpm -
Conectiva 5.1 i386 netscape-common-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/netscape-common-4.77-1cl.
i386.rpm -
Conectiva 5.1 i386 netscape-communicator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/5.1/i386/netscape-communicator-4.7
7-1cl.i386.rpm -
Conectiva 6.0 i386 netscape-common-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/netscape-common-4.77-1cl.
i386.rpm -
Conectiva 6.0 i386 netscape-communicator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/6.0/RPMS/netscape-communicator-4.7
7-1cl.i386.rpm -
Conectiva ecommerce i386 netscape-common-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/netscap
e-common-4.77-1cl.i386.rpm -
Conectiva ecommerce i386 netscape-communicator-4.77-1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/ferramentas/ecommerce/i386/netscap
e-communicator-4.77-1cl.i386.rpm - Conectiva ecommerce i386 netscape-navigator-4.
参考网址
来源: XF
名称: netscape-javascript-access-data(6344)
链接:http://xforce.iss.net/static/6344.php
来源: REDHAT
名称: RHSA-2001:046
链接:http://www.redhat.com/support/errata/RHSA-2001-046.html
来源: DEBIAN
名称: DSA-051
链接:http://www.debian.org/security/2001/dsa-051
来源: BUGTRAQ
名称: 20010409 Netscape 4.76 gif comment flaw
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=98685237415117&w=2
来源: BID
名称: 2637
链接:http://www.securityfocus.com/bid/2637
来源: OSVDB
名称: 5579
链接:http://www.osvdb.org/5579
来源: IMMUNIX
名称: IMNX-2001-70-014-01
链接:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-014-01
来源: CONECTIVA
名称: CLA-2001:393
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000393