impad4d Vulnerability & Patch Released
Last Updated: 2005-09-12 18:39:41 UTC
by Tony Carothers (Version: 3)
Patch Link
http://savannah.gnu.org/patch/index.php?func=detailitem&item_id=4407
Vulnerability Link
http://www.idefense.com/application/poi/display?id=303
GNU Mailutils information
http://www.gnu.org/software/mailutils/mailutils.html
Tony Carothers
Handler on Duty
Firefox 1.5 beta 1 released
Last Updated: 2005-09-12 15:14:44 UTC
by Tony Carothers (Version: 3)
One of our readers, Matthew, submitted that there is a new version of Firefox available for download. The latest version of the Firefox web browser, 1.5, is out in beta 1. After personally installing it earlier today I have found it be incredibly stable and feature rich. According to Mozilla, Firefox 1.5 beta 1 is still vulnerable to the IDN buffer overflow vulnerability published on Sep. 8th. It is highly recommended that all users take the steps indicated in the link below to secure against this vulnerability.
Patch information
https://addons.mozilla.org/messages/307259.html
Tony Carothers
Handler on Duty
Netscape URL Domain Name Buffer Overflow
Last Updated: 2005-09-11 00:37:23 UTC
by Koon Yaw Tan (Version: 2)
[Update 1]
Below is contributed by Juha-Matti on a workaround on this issue:
Manual about:config method for disabling IDN support works fully in Netscape Browser 8 (the newest version 8.0.3.3 was tested) too due to the same Firefox codebase.
Netscape 8 has the same about:config preference "network.enableIDN" in use and the same Filter dialog box when searching the exact preference name. A xpi patch file is not purposed to Netscape, because it will modify the UA string directly (adding "no IDN").
Instructions (same as Mozilla.org FF/Mozilla):
1. Type about:config into the address field and hit Enter.
2. In the Filter toolbar, type network.enableIDN.
3. Right click on the the network.enableIDN item and select Toggle to change value to false.
Comments
Please choose a specific diary above to comment

Diary Archives