Re: Netscape and Opera crash via java

From: Wayne D. Hoxsie Jr. (wayneat_private)
Date: Fri Mar 28 2003 - 11:04:55 PST

  • Next message: Eric Hines: "[logs] Fate Research Labs Presents: Analysis of the NTDLL.DLL Exploit"

    On Fri, 28 Mar 2003, Marc Schoenefeld wrote:
    
    > -----BEGIN PGP SIGNED MESSAGE-----
    > Hash: SHA1
    >
    > Hi,
    >
    > executing
    >
    > <scr1pt language="Javascript">
    > t = new Packages.sun.plugin.javascript.navig5.JSObject(1,1);
    > </scr1pt>
    >
    > crashes Netscape 7.02 and Opera 7 on Windows XP.
    > The active JVM in both tested browsers is Java 1.4.1_02 from Sun.
    >
    > This liveconnect (javascript-2-java-communication) stuff seems
    > to be still very dangerous.
    >
    > Sincerely
    > Marc Schoenefeld
    
    I tested it on the two versions of linux/mozilla I have immediately
    available:
    
    Crashes Mozilla 1.2a
      (Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.2a) Gecko/20020910)
    
    Does not crash Mozilla 1.0
      (Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.0.0) Gecko/20020605)
    
    -- 
    Wayne D. Hoxsie Jr.
    wayneat_private
    http://www.hoxnet.com
    PGP Key ID 138BCEE1
    



    This archive was generated by hypermail 2b30 : Fri Mar 28 2003 - 13:20:17 PST