Vulnerability Development mailing list archives

Re: Information Leak Bug Discovered in Netscape Mail!


From: 3APA3A <3APA3A () SECURITY NNOV RU>
Date: Thu, 22 Nov 2001 12:08:59 +0300

Hello vuln-dev,

You  should  check  Bugtraq  articles  before  posting it to lists. This
information  was  posted  in  Bugtraq by SECURITY.NNOV. You can find our
original advisory on

http://www.security.nnov.ru/advisories/netscape1.asp

Bugtraq archieve:

http://www.securityfocus.com/cgi-bin/archive.pl?id=1&start=2001-11-19&end=2001-11-25&mid=188748&threads=1

--Thursday, November 22, 2001, 6:12:23 AM, you wrote to vuln-dev () securityfocus com:

vd> Hello again everyone! 

vd> We at GOBBLES Research have discovered an insecure condition in Netscape 
vd> mail which could assist an attacker in gaining important information 
vd> regarding the accounts of those who use the client.  Attached is a copy of 
vd> our advisory, discussion on the vulnerability, and a proof-of-concept 
vd> exploit for the condition. 

vd> Enjoy! 

vd> The GOBBLES Research Team
vd> http://www.bugtraq.org 


-- 
~/ZARAZA
Ñýð Èñààê Íüþòîí îòêðûë, ÷òî ÿáëîêè ïàäàþò íà çåìëþ. (Òâåí)


Current thread: