积极预防 及时发现
快速响应 力保恢复
Netscape Communication早于4.77的版本允许远程攻击者通过指定一个特殊的精巧设...
发布时间:2001-08-02 信息来源:管理员

CNCVE编号:CNCVE-20010596 CVE编号:CAN-2001-0596 安全级别:高 漏洞中文描述: Netscape Communication早于4.77的版本允许远程攻击者通过指定一个特殊的精巧设计的GIF图片来执行任意的javascript脚本,这个javascript作为批注嵌入在GIF文件中。 漏洞英文描述: Netscape Communicator prior to 4.77 allows a remote attacker to execute arbitrary javascript via specially crafted GIF images. The javascript is embedded in the GIF file as a comment. 漏洞参考: Reference: BUGTRAQ:20010409 Netscape 4.76 gif comment flaw Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98685237415117&w=2 Reference: DEBIAN:DSA-051 Reference: URL:http://www.debian.org/security/2001/dsa-051 Reference: CONECTIVA:CLA-2001:3 系统类型: Unix/Linux Win95/98/ME Win2000/NT Apple其他 漏洞类型:设计错误