Re: [Full-Disclosure] Re: [sec-labs] Adobe Acrobat Reader <=5.0.7 Buffer Overflow Vulnerability + PoC code

From: KF (dotslashat_private)
Date: Mon Jul 07 2003 - 16:15:06 PDT

  • Next message: Paul Szabo: "Re: [Full-Disclosure] Re: [sec-labs] Adobe Acrobat Reader <=5.0.7 Buffer Overflow Vulnerability + PoC code"

    I left out one important part... I am guessing that this can only be 
    triggered if you are using Netscape browser?
    
    If you dont use netscape instead of WWWLaunchNetscape() getting called 
    it calls WWWLaunchOtherBrowser()?
    
    -KF
    
    
    KF wrote:
    
    > I could not reproduce this with the following files on linux:
    >
    >>
    >>         There is buffer overflow vulnerability in WWWLaunchNetscape 
    >> function. It 
    >
    ...
    
    >>
    >>  User also have to have netscape browser in preferences,   
    >>
    >
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >
    
    
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    



    This archive was generated by hypermail 2b30 : Mon Jul 07 2003 - 17:00:33 PDT