| Test ID: | 1.3.6.1.4.1.25623.1.0.900395 |
| Category: | Denial of Service |
| Title: | Netscape 'select()' Object Denial Of Service Vulnerability (Linux) |
| Summary: | Check for the version of Netscape |
| Description: |
Overview: This host is installed with Netscape browser and is prone to Denial of Service vulnerability.
Vulnerability Insight: Error occurs while calling the 'select()' method with a large integer that results in continuous allocation of x+n bytes of memory exhausting memory after a while.
Impact: Successful exploitation will allow attacker to cause a denial of service by exhausting memory.
Impact Level: System/Application
Affected Software/OS: Netscape version 6 and 8 on Linux
Fix: No solution or patch is available as of 28th July, 2009, Information regarding this issue will be updated once the solution details are available. For updates refer to http://browser.netscape.com/
References: http://www.milw0rm.com/exploits/9160 http://www.g-sec.lu/one-bug-to-rule-them-all.html http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded |
| Cross-Ref: |
BugTraq ID: 35446
Common Vulnerability Exposure (CVE) ID: CVE-2009-2542
Bugtraq: 20090715 Re: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... (Google Search)
http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded
Bugtraq: 20090715 Re:[GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... (Google Search)
http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded
Bugtraq: 20090715 [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... (Google Search)
http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded
Bugtraq: 20090716 Re[2]: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3.... (Google Search)
http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded
http://www.milw0rm.com/exploits/9160
http://www.g-sec.lu/one-bug-to-rule-them-all.html
XForce ISS Database: netscape-integer-value-dos(52876)
http://xforce.iss.net/xforce/xfdb/52876
Common Vulnerability Exposure (CVE) ID: CVE-2009-1692
https://bugs.webkit.org/show_bug.cgi?id=23319
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
Debian Security Information: DSA-1950 (Google Search)
http://www.debian.org/security/2009/dsa-1950
SuSE Security Announcement: SUSE-SR:2011:002 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
BugTraq ID: 35414
http://www.securityfocus.com/bid/35414
http://www.securityfocus.com/bid/35446
http://osvdb.org/55242
http://secunia.com/advisories/37746
http://secunia.com/advisories/43068
http://secunia.com/advisories/36977
http://www.vupen.com/english/advisories/2009/1621
http://www.vupen.com/english/advisories/2011/0212
|
| Copyright | Copyright (C) 2009 SecPod |