Version: 2008

October 22, 1998 2:30 PM PDT

Unix users face Navigator bug

  • Post a comment
Related Stories

Netscape ships Communicator 4.5

October 19, 1998

O'Reilly addresses crypto laws

October 13, 1998

Navigator still has bug problem

October 7, 1998

Navigator update stamps out bug

October 5, 1998

Bugs infest high tech

September 29, 1998

Navigator bug exposes browser history

September 28, 1998
Netscape Communications today acknowledged a bug in its Navigator browser that could make users on the Unix operating system vulnerable to attack.

A page describing the problem was posted to the Web this week by programmer Dan Brumleve. Brumleve recently discovered and demonstrated two Navigator privacy bugs, both of which revealed users' cache, browsing history, and other information.

The present bug allows a malicious programmer to flood the browser's MIME-type memory and cause the application to crash. Brumleve suggests that malicious code could then be caused to run on the victim's computer, but Netscape said no such exploit has been demonstrated.

The attack is launched when the user tries to download an attacker's plug-in. Netscape suggests that Unix users using Navigator work around the problem by setting preferences to present a warning before the plug-in can be downloaded: Under application preferences, users should select unknown plug-ins (denoted by an asterisk), select the "edit," button, and set it to "unknown:prompt user."

Netscape said it would post a security alert on the bug today and that it was working on a fix. But Communicator product manager Micki Seibel said that, unless the company finds evidence that the hole has effectively been exploited, no special release of a patched browser would be issued ahead of schedule.

The bug affects versions 3.x, 4.0x, and 4.5 of the client for users on the Unix platform only.

advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (-0.02%) -1.67 10,545.41
S&P 500 (-0.14%) -1.58 1,126.20
NASDAQ (-0.12%) -2.68 2,288.40
CNET TECH (-0.06%) -1.08 1,661.09
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right