Netscape 7.02 Client Detection Tool plug-in buffer overrun

From: martin rakhmanoff (jimmers_at_yandex.ru)
Date: 07/14/03

  • Next message: Janusz Niewiadomski: "Linux nfs-utils xlog() off-by-one bug"
    Date: 14 Jul 2003 14:48:24 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Advisory name
    =============

    Netscape 7.02 Client Detection Tool plug-in buffer overrun

    Affected software
    =================

    Netscape 7.02 for Windows

    Problem description
    ===================

    Netscape 7.02 (and probably earlier versions) contains Client Detection
    Tool plug-in that handles application/x-cdt Mime type. One of this plug-in
    routines suffers from buffer overrun. To exploit this issue one needs to
    send mail message to victim with attachment that has specifically crafted
    filename and entice the victim to double-click it. When the victim double
    clicks the attachment then attacker's code is executed in context of
    victim's user account. Proof-of-concept exploit is published in whitepaper
    "CDT plug-in bug: exploit in ASCII":

    http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf

    Mitigating factors
    ==================

    Attacker must know OS and length of victim username to exploit this issue.
    Also proof-of-concept exploit assumes that user runs Windows with default
    settings.

    Resolution
    ==========

    Manually remove CDT plug-in (npcdt.dll) from Netscape /components folder
    or upgrade to latest version of the browser that has CDT plug-in removed.

    Vendor status
    =============

    Netscape was notified. Netscape considers this bug as "internal" so no
    patch will be released.

    Copyright (c) 2003 Martin Rakhmanov.


  • Next message: Janusz Niewiadomski: "Linux nfs-utils xlog() off-by-one bug"

    Relevant Pages

    • Re: No Non-Microsoft browser support? What happned?
      ... Firefox had an interesting architectural choice to make a ways back - ... architecture that the Windows Media Player 6 Netscape plug-in uses. ...
      (microsoft.public.windowsmedia.player)
    • Getting Crescendo to Play in Netscape 7
      ... listed as a Netscape Plug-in. ... I have Windows Media Player embedded in IE and it will play the midi on my ... But when I go to Netscape the midi won't play even though I have Crescendo ...
      (microsoft.public.windowsxp.music)
    • Getting Crescendo to Play in Netscape 7
      ... listed as a Netscape Plug-in. ... I have Windows Media Player embedded in IE and it will play the midi on my ... But when I go to Netscape the midi won't play even though I have Crescendo ...
      (microsoft.public.windowsxp.music)
    • Re: Crescendo Plug-in
      ... >> opened up Netscape and looked at Plug-ins it wasn't listed, ... >Did you do a Windows search for the Crescendo plug-in? ... >> in Netscape and what I can do to get it to install to Netscape? ... >forum, or in the NS newsgroups for some free advice. ...
      (microsoft.public.windowsxp.music)
    • Re: online religion test - do you believe in God?
      ... Goddess only knows what the plug-in does. ... track of which web sites a victim visits, and mails the results to the ...
      (talk.origins)