FF IDN buffer overflow workaround works in Netscape too

From: Juha-Matti Laurio (juha-matti.laurio_at_netti.fi)
Date: 09/16/05

  • Next message: innate_at_gmx.de: "worring about YaST in SuSE 9.3 and maybe lower"
    Date: Fri, 16 Sep 2005 01:27:09 +0300 (EEST)
    To: bugtraq@securityfocus.com
    
    

    Summary about Firefox IDN buffer overflow vulnerability workarounds in
    Netscape Browser

    [a new, more informative title used]

    Instructions and methods described at Mozilla Foundation Security
    Advisory "What Firefox and Mozilla users should know about the IDN
    buffer overflow security issue"
    https://addons.mozilla.org/messages/307259.html (yes, it was
    http://www.mozilla.org/security/idn.html earlier) can be used in Netscape too.
    This advisory has been included to security company advisories handling
    this security issue and mentioned in the news widely.

    Disabling IDN (Internationalized Domain Names) support via about:config
    Location Bar
    feature or prefs.js configuration file is possible in Netscape Browser 8
    too. Additionally, .xpi file for Firefox and Mozilla Suite works in
    Netscape 8.0.3.3 too. Test in Windows environment was successful and
    even UA was changed to include '....Gecko/20050729 <<(No IDN)>>
    Netscape/8.0.3.3' string.
    However, the manual method is recommended.
    Vendor developer team was contacted, no reply yet.

    Like US-CERT says in Firefox VU#573857: "While implementing this
    workaround does not correct the buffer overflow error, it prevents the
    vulnerable portion of code from being exploited."

    When an updated version of Netscape Browser 8 is available the download
    link is http://browser.netscape.com/ns8/download/default.jsp

    Regards,
    Juha-Matti Laurio
    Security researcher
    Finland


  • Next message: innate_at_gmx.de: "worring about YaST in SuSE 9.3 and maybe lower"

    Relevant Pages

    • [Full-disclosure] FF IDN buffer overflow workaround works in Netscape too
      ... Instructions and methods described at Mozilla Foundation Security ... Advisory "What Firefox and Mozilla users should know about the IDN ... feature or prefs.js configuration file is possible in Netscape Browser 8 ...
      (Full-Disclosure)
    • Re: [Full-disclosure] FireFox Host: Buffer Overflow is not just exploitable on FireFox
      ... >IDN Heap Buffer overrun in FireFox on WinXP and Win2k3 as long as DEP is ... It has also revealed that not only FireFox is ... An official security URL to Netscape is "Netscape Browser Bug Submission ...
      (Full-Disclosure)
    • RE: [Full-Disclosure] IE is just as safe as FireFox
      ... little happier running windows. ... Back on topic though, IE is no where near Firefox for security, however, ... More infinate wisdom there Rafel. ...
      (Full-Disclosure)
    • Re: OT: Computers
      ... We need a serious change in the security paradigm. ... remediate all 40 on his own weekend time just because he's the one stuck ... And Firefox alone has grabbed a *huge* chunk of Explorer's market over the past two years. ... PS: perhaps one of the shifts will be having PCs with locked hard drives that just contain the basics: the OS, a browser, etc... ...
      (rec.gambling.poker)
    • Re: Critical error 101 on MS AntiSpyware install
      ... Not to mention everyone and their brother that is on the firefox high ... low and behold - Windows Help opens up - hum, ... because the one thing that was on on my little browser was the little ... Just use windows security, and not ignore ...
      (comp.security.misc)