1997-06-13 - Re: Netscape Bug :)))

Header Data

From: “William H. Geiger III” <whgiii@amaranth.com>
To: ichudov@Algebra.COM (Igor Chudov @ home)
Message Hash: 4d387e93808b977bfcefd5c183f17b0f94b939f0b2dc9253e6cd8b299208a4a3
Message ID: <199706130353.WAA05560@mailhub.amaranth.com>
Reply To: <199706130347.WAA08219@manifold.algebra.com>
UTC Datetime: 1997-06-13 04:01:14 UTC
Raw Date: Fri, 13 Jun 1997 12:01:14 +0800

Raw message

From: "William H. Geiger III" <whgiii@amaranth.com>
Date: Fri, 13 Jun 1997 12:01:14 +0800
To: ichudov@Algebra.COM (Igor Chudov @ home)
Subject: Re: Netscape Bug :)))
In-Reply-To: <199706130347.WAA08219@manifold.algebra.com>
Message-ID: <199706130353.WAA05560@mailhub.amaranth.com>
MIME-Version: 1.0
Content-Type: text/plain



-----BEGIN PGP SIGNED MESSAGE-----

In <199706130347.WAA08219@manifold.algebra.com>, on 06/12/97 
   at 10:47 PM, ichudov@Algebra.COM (Igor Chudov @ home) said:

>William H. Geiger III wrote:
>> Seems that there is a bug in Netscape including the new Communicator that
>> will allow a web site to read *ANY* file on your computer. I repeate
>> *ANY*, yes Virginia, *ANY* file on your computer.
>> 
>> WebEx user and loving it. :)))))

>Do you know if the bug affects Unix versions? How about linux?

>And what is the exploit?

They didn't go into details but they did say in the report that it was a
bug in the "core" of the Netscape code so I would imagine that it is cross
platform.

Unfortunatly they did give details on how to use this bug.

This seems to be a bug that has been out for awhile as it is not just the
new Communicator but older versions of NS also.

Perhaps time to generate a new PGP key pair? :(

- -- 
- ---------------------------------------------------------------
William H. Geiger III  http://www.amaranth.com/~whgiii
Geiger Consulting    Cooking With Warp 4.0

Author of E-Secure - PGP Front End for MR/2 Ice
PGP & MR/2 the only way for secure e-mail.
OS/2 PGP 2.6.3a at: http://www.amaranth.com/~whgiii/pgpmr2.html                        
- ---------------------------------------------------------------

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3a
Charset: cp850
Comment: Registered_User_E-Secure_v1.1b1_ES000000

iQCVAwUBM6DFQ49Co1n+aLhhAQF8WAQAu5mdShPAlsCQUSQjb2tMtMwQD/o7KFhy
hxZB2mv3dMZmdNzZxpspQslO3V11teL3aeN9lE+5NIHJtV3mO6Zhq8ScOo6nQb6L
1EC47wroVGB3H7FeIf8Ol6xfzu1fZf6KawvIrPu83rbte8RQ50KE+Q09CB8wMS69
U06XJWyktLc=
=QEUX
-----END PGP SIGNATURE-----






Thread