Version: 2008
  • On MovieTome: See the villain of IRON MAN 2!

October 7, 1998 1:45 PM PDT

Navigator still has bug problem

  • Post a comment
Related Stories

Navigator update stamps out bug

October 5, 1998

Bugs infest high tech

September 29, 1998

Navigator bug exposes browser history

September 28, 1998

Buffer-overflow bug in IE

August 19, 1998

Netscape updates Communicator

August 17, 1998
Navigator users who installed Netscape Communications' latest update to fix a privacy bug may find themselves doing the exact same thing in the next few weeks.

The firm today acknowledged the existence of a privacy bug in its Navigator browser that could reveal users' cache, cookies, and file directory information to a malicious Web site operator.

It is the second such privacy hole that has surfaced in as many weeks for Navigator; a similar bug that exposed the user's cache file surfaced late last month. Both were discovered by programmer Dan Brumleve.

Dubbed "Son of Cache Cow," following the "Cache Cow" bug that Brumleve demonstrated, the current bug lets a Web site operator use a JavaScript to snatch a visitor's browser cache, cookie files, and directory file information. Brumleve has posted a demonstration of the new exploits on the Web.

JavaScript is a scripting language, unrelated to the Java programming language, for interactive Web documents such as pop-up windows and forms. The browser cache holds copies of recently downloaded Web pages for faster subsequent retrieval. Cookie files are digital tags that Web sites place on a visitor's hard drive to store information such as the visitor's purchases, user name, and password.

Netscape said it was looking into the problem and expected to post a fix within the next two weeks. Neither the company nor Brumleve suggested a work-around. Users, however, are able to set their browser preferences to disable JavaScript and/or refuse cookies. For the prior problem, Netscape recommended that users set their cache size to zero to work around it temporarily.

Netscape moved quickly to turn around a software fix for Brumleve's last privacy bug, posting an updated version of Communicator (the Internet software suite of which Navigator is the browsing component) just over a week after learning of the problem. The new bug affects the latest version of Communicator, 4.07.

In addition to posting a fix or an update in the next two weeks, Netscape also will address the problem in the upcoming release of Communicator 4.5, which is currently in its second beta phase. Also included in the 4.5 release will be a fix for a serious Java security hole discovered in July.

advertisement

Latest tech news headlines

advertisement

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.72%) 73.00 10,270.47
S&P 500 (0.57%) 6.24 1,093.48
NASDAQ (0.88%) 18.86 2,167.88
CNET TECH (0.63%) 9.86 1,587.17
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right