Vector: | Remote |
Severity: | Low |
Patch: | Patched |
Impact: | Remote Code Execution (RCE) |
Software: | Netscape 7.x |
A remote code execution vulnerability was discovered in Netscape Client Detection Tool.
Buffer overflow vulnerability exists in the Client Detection Tool (CDT) plug-in. An attacker can exploit this vulnerability by sending an email with a specially crafted attachment to a user, which may cause a buffer overflow and allow execution of arbitrary code with the user's privileges.
Solution:
For : Remove the plug-in (npcdt.dll), or update to the latest version, which doesn't include the affected plug-in.
Links:
http://jimmers.russia.webmatrixhosting.net/whitepapers/CDTbug.pdf