Netscape/Mozilla IRC缓冲区溢出漏洞

漏洞信息详情

Netscape/Mozilla IRC缓冲区溢出漏洞

漏洞简介

Netscape 6和Mozilla 1.0 RC1及其之前版本存在缓冲区溢出漏洞。远程攻击者借助IRC URI中的超长通道名导致服务拒绝(崩溃)且可能执行任意代码。

漏洞公告

FreeBSD has released an updated version of ports which contains versions mozilla-1.0.rc1_2,1 of Mozilla for FreeBSD, and linux-mozilla-1.0_1 of Mozilla for Linux. The new version of ports may be downloaded from a ports mirror. See referenced advisory for more information.
Fixes are available:
Mozilla Browser 0.9.9

Mozilla Browser 1.0 RC1

参考网址

来源: BID
名称: 4637
链接:http://www.securityfocus.com/bid/4637

来源: BUGTRAQ
名称: 20020430 RE: Reading local files in Netscape 6 and Mozilla (GM#001-NS)
链接:http://online.securityfocus.com/archive/1/270249

来源: CONECTIVA
名称: CLA-2002:490
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490

来源: XF
名称: mozilla-netscape-irc-bo(8976)
链接:http://www.iss.net/security_center/static/8976.php

来源: SECUNIA
名称: 8039
链接:http://secunia.com/advisories/8039

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享