| Netscape embedded JavaScript in GIF file comments can be used to access remote data (NetscapeJavascriptAccessData) |
|---|
| Vuln ID: | 6344 | |
|---|---|---|
| Risk Level: | Medium |
NetscapeJavascriptAccessData |
| Platforms: | RedHat Linux: 6.2, Debian Debian Linux: 2.2, FreeBSD FreeBSD Ports Collection, Connectiva Linux, RedHat Linux: 7, Immunix Immunix OS: 6.2, Immunix Immunix OS: 7.0-beta, Immunix Immunix OS: 7.0, Netscape Communicator: 4.76, RedHat Linux: 7.1, RedHat Linux: 7.2, RedHat Linux: 7.3 | |
| Description: | Netscape Communicator could allow a malicious Web site operator to access data on a visiting user’s computer. The Netscape Navigator fails to properly escape Graphic Interchange Format (GIF) file comments in the image information page. A malicious Web site operator could exploit this vulnerability by inserting JavaScript in the GIF file comments to upload information from a visiting user’s computer to the Web server. An attacker can use this vulnerability to gain access to sensitive information, including the browser history. |
|
| Remedy: | Upgrade to the latest version of Netscape Communicator (4.77 or later), available from the Netscape Web site. See References. For Red Hat Linux 6.2: For Red Hat Linux 7.0 and 7.1: For Immunix OS 6.2: For Immunix OS 7.0-beta and 7.0: For Progeny Debian: For Conectiva Linux 4.0, 4.0es, 4.1, 4.2, 5.0, prg graficos, ecommerce, 5.1, 6.0: For Debian 2.2 potato: For FreeBSD Ports Collection (prior to 2001-04-07): For other distributions: |
|
| Additional Information: | Service Release 3.09 | |
| References: | BugTraq Mailing List, Mon Apr 09 2001 - 06:48:26 CDT RHSA-2001:046-05 Netscape Communications, Inc. Web site Immunix OS Security Advisory IMNX-2001-70-014-01 Progeny Linux Systems Security Advisory PROGENY-SA-2001-07 Conectiva Linux Announcement CLSA-2001:393 DSA-051-1 FreeBSD Security Advisory FreeBSD-SA-02-16 ISS X-Force CVE CVE-2001-0596 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |