|
Netscape Communicator Long Argument Vulnerability
Netscape Communicator 4.7 has been shown to crash when an argument of 800 characters is supplied to a command in an interactive web page (.asp, .cgi, .pl etc). Some of the data passed as the argument makes it into the EIP and EBP registers, so execution of arbitrary code is a possibility. The overflow could be embedded in a link on a webpage or in an email message for remote attacks. |
|
|
Privacy Statement |