|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Netscape Communications Corporation Information for VU#980499
| Date Notified | 03/30/2001 |
| Date Modified | 03/05/2004 11:37:45 AM |
| Status Summary | Not Vulnerable |
Vendor StatementWe have concluded that the bug, as described below, does NOT affect Netscape clients 4.x and 6.x for the following two reasons:
- We ALWAYS verify that the user wants to open/launch the attachment with a link. The user must click this link to view/launch the attachment.
- Also, we ALWAYS stay true to the MIME type given. Therefore, if someone sent a malicious .exe file, and manually changed the MIME type to image/gif, Netscape would open the file as a gif. The result would be garbled binary code.
As a result of our forced check for user authorization (bullet #1) we assume that the bug in question does not affect us.
US-CERT AddendumThe CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |