| SD701 > MozInfo701 > 2005 Sep > IDN buffer overflow security issue |
| News | Directory | Mozilla Products | Netscape | Switch Guide | Support Forum |
9 September, 2005IDN buffer overflow security issueby Don_HH2K
"Host:" Paramater Buffer Overflow Vulnerability SillyDog701 member J-M recently posted to the Message Centre about a new vulnerability in Firefox and other Mozilla-based products. A vulnerability has been identified in Mozilla Firefox, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to a buffer overflow error in the "NormalizeIDN" function when handling specially crafted URLs embedded in "HREF" tags, which could be exploited by remote attackers to take complete control of an affected system via specially crafted Web pages. It has been reported that this vulnerability affects Firefox 1.0.6 and prior versions, as well as Netscape 8.0.3.3, Mozilla Suite 1.7.11, and Firefox 1.5 Beta 1. A patch has been released by The Mozilla Foundation to temporarily resolve this issue. Continue reading about the "Host:" Parameter Remote Buffer Overflow Vulerability at the SillyDog701 Message Centre. Posted by Don_HH2K at September 9, 2005 07:50 PM >> more September 2005 stories. Talkback
Post a comment
|
featured articles
Relationship between Netscape, Mozilla, a quick guide and a historical perspective.
Using common Mozilla/Netscape profile for dual booting, single Netscape/Mozilla profile for Linux and Windows. Teach Netscape 6/7 to remember newsgroup passwords. Use Firefox as the only rendering engine in Netscape 8, how to disable Site Control. search
inside SillyDog701:
Message Centre (forums)
UserAgent strings, our very unique feature in SillyDog701 Message Centre. "Very Netscape" wallpaper, free desktop wallpaper. Feedback
|
| Page URL: http://moz.sillydog.org/archives/000853.php
[SillyDog701] [MozInfo701] [Switch Guide] [MacCentre701] [Search] [Change Log] [Contact Us] [About Us] [Sitemap] Copyright © 2003 - 2011 SillyDog701. All rights reserved. Copyright Notice. Privacy Statement. |
support MozInfo701 and MozInfo701 |