NODE 9d6f97e6Re: Another Netscape Bug (and possible security hole)
donlonm@ccmail.mcclellan.af.milWed, 27 Sep 95 10:23:54 PDT
Ray,
You wrote:
>I've found a Netscape bug which I suspect is a buffer overflow and
>may have the potential for serious damage. If it is an overflow bug,
>then it may be possible to infect every computer which accesses a web
>page with Netscape.
Is there any way to avoid/prevent this problem by changing options in
NetScape?
Thanks,
Mike D.
NODE eaf8d663Re: Another Netscape Bug (and possible security hole)
futplex@pseudonym.com (Futplex)Wed, 27 Sep 95 20:44:36 PDT
Ray Cromwell writes:
# I've found a Netscape bug which I suspect is a buffer overflow and
# may have the potential for serious damage.
Mike D. writes:
> Is there any way to avoid/prevent this problem by changing options in
> NetScape?
I'm afraid there's no way to completely eliminate the problem without getting
the next version of Netscape. There's no apparent way to increase the size of
the buffer allocated for a URL at runtime. Of course, that would only be of
limited use. Certainly there's no way for a user to really fix the problem by
adding a check on the length of the URL.
However, a certain amount of common sense will go a long way in avoiding ugly
incidents. To put it simply, "look before you leap". Before you click on a
link, look at the status bar at the bottom of the Netscape window (in the
Unix version at least) that displays the URL of the link under the pointer.
To be safe, if it's too long to fit entirely in the status bar, view the
source of the current page to find the complete URL. (Note that when a URL is
too long to fit completely in the status bar, a middle portion of it is elided
with "...")
Also, if the link is labelled "Don't click here !" like one on my homepage,
don't click there ! :}
-Futplex <futplex@pseudonym.com>
"What if you knew her, and found her dead on the ground ?
How can you run when you know ?" -Neil Young
NODE 0edb19c9Re: Another Netscape Bug (and possible security hole)
jsw@neon.netscape.com (Jeff Weinstein)Wed, 27 Sep 95 22:49:54 PDT
In article <9508278122.AA812233405@ax.asc-yf.wpafb.af.mil>, donlonm@ccmail.mcclellan.af.mil writes:
> Ray,
>
> You wrote:
>
> >I've found a Netscape bug which I suspect is a buffer overflow and
> >may have the potential for serious damage. If it is an overflow bug,
> >then it may be possible to infect every computer which accesses a web
> >page with Netscape.
>
> Is there any way to avoid/prevent this problem by changing options in
> NetScape?
Just get the fixed version, or a patch from:
ftp://ftp.netscape.com/pub/netscape/
--Jeff
--
Jeff Weinstein - Electronic Munitions Specialist
Netscape Communication Corporation
jsw@netscape.com - http://home.netscape.com/people/jsw
Any opinions expressed above are mine.