Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 







Current Newswire:

Intel Linux Graphics Shine With Fedora 12

Editor's Note: Do It Yourself "Cloud"

Google Chrome OS: First looks, first impressions

Kernel Log: Coming in 2.6.32 (Part 3) - Storage

TV Mythos Renewed: MythTV 0.22 with Many Improvements

Enhancing openSUSE 11.2: Adding Repositories and Packages

A Northwest Nobel option? (Linus for the Nobel Peace prize)

SECURITY: Cloud Computing Security Benefits, Risks and Recommendations

Keeping score in test-driven development with Python, PyLint, unittest, doctest,

Win a CodeWeavers Linux Gaming Rig




Sr Systems Engineer - Solaris - AIX (TX)
Next Step Systems
US-TX-Houston

Justtechjobs.com Post A Job | Post A Resume
:Smart Partner: Serious Security Hole Found In Netscape's Java
Smart Partner: Serious Security Hole Found In Netscape's Java
Aug 8, 2000, 14 :14 UTC (2 Talkback[s]) (4784 reads)

(Other stories by Chris DeVoney)

"A serious vulnerability has been found in a version of Netscape Navigator and Netscape Communicator Java interpreter that allows Web-based programs to access virtually any file. The vulnerability also lets the same Java code act like Windows Explore and can browse and access files on other computers that are visible from the exploited computer."

"The problem affects all versions of Netscape Navigator and Netscape Communicator 4.74 and earlier when Java and downloadable plug-ins are enabled on Windows 9x, Windows NT/2K and Linux. The current beta version of the product, Mozilla, is not now vulnerable nor is any version of Microsoft Internet Explorer. The problem will not occur on any affected Netscape browser if Java disabled."

"The security hole, describe by secure experts as "serious," allows Web-based Java code to start a server process on the machine with the Netscape client. The Web-based programs could be used in a Web page by a malicious Web site or by a malicious person who hacks into a Web site and plants the code in a Web page."

Complete Story

Related Stories:
TurboLinux Security Announcement: Package: netscape-4.73 and earlier(Aug 02, 2000)
Red Hat Security Advisory: New netscape packages available to fix JPEG problem(Jul 31, 2000)
The Register: Netscape's disappearing privacy code(May 10, 2000)
PC Week: Vulnerability discovered in Netscape Navigator(Apr 21, 2000)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
If you want to see this in action go her ...   Try it here   
mike
Aug 8, 2000, 14:47:58
 
Well, I just tried on a dumb directory a ...   Sweet ol Firewall   
Thomas
Aug 8, 2000, 19:24:32
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP

internet.commediabistro.comJusttechjobs.comGraphics.com

Search:

WebMediaBrands Corporate Info

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs