Skip to main content

Overflow Vulnerability in Netscape SmartDownload

posted onApril 14, 2001
by hitbsecnews

"Netscape SmartDownload is a browser plugin that allows users to pause and resume downloads from the Internet. It can be installed separately, or when installing Netscape's Communicator. If enabled, SmartDownload can handle downloads spawned by both Netscape and Microsoft Internet Explorer, possibly others. However, if SmartDownload was installed and subsequently "disabled," the system will still be vulnerable to attack."

"SmartDownload parses all URLs that the web browser accesses. As part of the parsing, it copies the file requested using an unbounded string operation to a buffer on the stack, allowing a classic overwrite of the saved instruction pointer, and potential execution of malicious code."

"Because SmartDownload installs plugins for all browsers it supports by default (which includes both Netscape Communicator and Microsoft Internet Explorer), most users who have SmartDownload on their system are vulnerable to this condition. Because SmartDownload parses all outgoing requests, the condition can be exploited very easily, and does not always require the user to click or actively request a link."

Get the Full Details from @Stake

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th