1997-06-14 - Re: Impact of Netscape kernel hole

Header Data

From: ichudov@Algebra.COM (Igor Chudov @ home)
To: tomw@netscape.com (Tom Weinstein)
Message Hash: de3e599a5447c3c2d6270b415df7cd7e9f301a46d24dbf726478bc11ca21852e
Message ID: <199706140232.VAA20313@manifold.algebra.com>
Reply To: <33A1F574.42D6AD6A@netscape.com>
UTC Datetime: 1997-06-14 02:59:05 UTC
Raw Date: Sat, 14 Jun 1997 10:59:05 +0800

Raw message

From: ichudov@Algebra.COM (Igor Chudov @ home)
Date: Sat, 14 Jun 1997 10:59:05 +0800
To: tomw@netscape.com (Tom Weinstein)
Subject: Re: Impact of Netscape kernel hole
In-Reply-To: <33A1F574.42D6AD6A@netscape.com>
Message-ID: <199706140232.VAA20313@manifold.algebra.com>
MIME-Version: 1.0
Content-Type: text



Tom Weinstein wrote:
> John Young wrote:
> > 
> > Still, it would be good to know if a Netscape snooper could snarf a
> > key while it is being used by PGP to decrypt, that is, whether the
> > hole allows snooping on dynamic ops or just on stored info.
> > 
> > Does anyone know if the the hole finders are discussing this on the
> > Net, and if so, where? What are the folks at Netscape saying? Tom,
> > Jeff?
> 
> We aren't talking about it much.  We've released some information to
> the press and posted a release on our web site.
> 
> This attack can be used to grab any file from the user's hard drive,
> provided you know the file name and path.  It exploits a bug in the
> way forms are handled.  You can guard against this attack by turning
> on the warning dialog for submitting a form over an insecure connection.
> 
> We have a fix which we are testing now, and we'll have it out early next
> week for 4.0.  A fix for 3.x will follow once we have 4.0 fixed.


Tom, are you going to release the linux version of netscape, 
and when.

Thank you very much.

	- Igor.






Thread