Netscape 7.02 DoS security flaw reported

Composer, ChatZilla and other Mozilla applications, along with Netscape, Galeon, K-Meleon and other products.
Post Reply
old Harry Waldron
Moderator
Posts: 0
Joined: December 31st, 1969, 5:00 pm

Netscape 7.02 DoS security flaw reported

Post by old Harry Waldron »

I'm sharing this as an FYI ... While these vulnerabilities might exist, I also see this as low risk overall.

Denial of Service in Opera 7 and Netscape 7.02 Browsers
http://www.secadministrator.com/Article ... leID=38590

Reported April 2, 2003, by Marc Schönefeld.


VERSIONS AFFECTED

* Netscape 7.02

* Opera 7 using Sun Microsystems' Java Virtual Machine (JVM), version 1.4.1_02


DESCRIPTION
A vulnerability in Netscape 7.02 and Opera 7 Web browsers can result in a Denial of Service (DoS) condition.


DEMONSTRATION
As proof of concept, the discover posted the following code, which crashes the browsers when they run on Windows XP:

<scr1pt language="Javascript">
t = new Packages.sun.plugin.javascript.navig5.JSObject(1,1);
</scr1pt>


VENDOR RESPONSE
Netscape and Opera haven't yet responded to this concern.
User avatar
Z_God
Posts: 267
Joined: November 5th, 2002, 7:56 am
Location: Netherlands, Enschede
Contact:

Post by Z_God »

Is there any webpage that contains that code so it is possible to try it out?
User avatar
willll
Posts: 2577
Joined: November 30th, 2002, 11:39 am
Location: Washington, DC

Post by willll »

yup, it fucks firebird, mozilla, and netscape, but strangely not k-meleon or opera.

its bugs 200016 and 199694 on bugzilla
User avatar
jgraham
Posts: 558
Joined: November 28th, 2002, 10:20 am
Location: Cambridge, UK
Contact:

Post by jgraham »

Okay, I'm confused. This just seems to be a way of crashing the browser. How is that a security flaw anymore than any of the other crash bugs reported are? Whst am I missing?
Post Reply