Package name
netscape
Date
2000-08-01
Advisory ID
MDKSA-2000:027-1
Affected versions
6.1 i586 , 6.0 i586 , 7.0 i586 , 7.1 i586

Problem description

Previous versions of Netscape, from version 3.0 to 4.73 contain a serious overflow flaw due to improper input verification in Netscape's JPEG processing code. The way Netscape processed JPEG comments trusted the length parameter for comment fields. By manipulating this value, it was possible to cause Netscape to read in an excessive amount of data which would then overwrite memory. Data with a malicious design could allow a remote site to execute arbitrary code as the user of Netscape on the client system. It is highly recommended that everyone using Netscape upgrade to this latest version that fixes the flaw. Update: The md5sums listed in the previous advisory are no longer valid. We are using the same RPM packages for 6.0, 6.1, and 7.0 so the md5ums have changed. The package for 7.1 has also been updated to incorporate many of the enhancements used in Linux-Mandrake 7.1

Updated packages

6.1 i586

 c036cb52e1498df0a0535fe7c72ebeac  6.1/RPMS/netscape-common-4.74-2mdk.i586.rpm
c15f7a002d8c1c131f3d8642f60bed97  6.1/RPMS/netscape-communicator-4.74-2mdk.i586.rpm
8cbd47dd868d9e2be8d234f118cee542  6.1/RPMS/netscape-navigator-4.74-2mdk.i586.rpm
ed04b0a2e33b011891661890f0fc5aa9  6.1/SRPMS/netscape-4.74-2mdk.src.rpm

6.0 i586

 c036cb52e1498df0a0535fe7c72ebeac  6.0/RPMS/netscape-common-4.74-2mdk.i586.rpm
c15f7a002d8c1c131f3d8642f60bed97  6.0/RPMS/netscape-communicator-4.74-2mdk.i586.rpm
8cbd47dd868d9e2be8d234f118cee542  6.0/RPMS/netscape-navigator-4.74-2mdk.i586.rpm
ed04b0a2e33b011891661890f0fc5aa9  6.0/SRPMS/netscape-4.74-2mdk.src.rpm

7.0 i586

 365ff8c6b19ea8f1ca189e6886f9fba8  7.0/RPMS/netscape-castellano-4.74-1mdk.noarch.rpm
c036cb52e1498df0a0535fe7c72ebeac  7.0/RPMS/netscape-common-4.74-2mdk.i586.rpm
c15f7a002d8c1c131f3d8642f60bed97  7.0/RPMS/netscape-communicator-4.74-2mdk.i586.rpm
573eaa96ade623548dbc6f4d87a2df98  7.0/RPMS/netscape-francais-4.74-2mdk.noarch.rpm
8cbd47dd868d9e2be8d234f118cee542  7.0/RPMS/netscape-navigator-4.74-2mdk.i586.rpm
c43957d0f00722111abfb90ac2028c97  7.0/RPMS/netscape-walon-4.74-1mdk.noarch.rpm
ed04b0a2e33b011891661890f0fc5aa9  7.0/SRPMS/netscape-4.74-2mdk.src.rpm
29d92c1962b636d0436311b76f980eeb  7.0/SRPMS/netscape-castellano-4.74-1mdk.src.rpm
701f6c3aa7b4b6cd800322b624f040e2  7.0/SRPMS/netscape-francais-4.74-2mdk.src.rpm
4e715744e0e66b487def62a4e750923d  7.0/SRPMS/netscape-walon-4.74-1mdk.src.rpm

7.1 i586

 365ff8c6b19ea8f1ca189e6886f9fba8  7.1/RPMS/netscape-castellano-4.74-1mdk.noarch.rpm
3c83d493cbada78ba6348e6581bcf523  7.1/RPMS/netscape-catalan-4.74-1mdk.noarch.rpm
9791a6e655b3f8a76a112c6c13c53534  7.1/RPMS/netscape-common-4.74-3mdk.i586.rpm
f34cc1d76f649556b51f2fafbfc2936f  7.1/RPMS/netscape-communicator-4.74-3mdk.i586.rpm
eedd08421fa0e6496dcb1ea575bf627c  7.1/RPMS/netscape-euskara-4.74-1mdk.noarch.rpm
573eaa96ade623548dbc6f4d87a2df98  7.1/RPMS/netscape-francais-4.74-2mdk.noarch.rpm
4f71f99e91182679b4c26a571e85bbbb  7.1/RPMS/netscape-navigator-4.74-3mdk.i586.rpm
c43957d0f00722111abfb90ac2028c97  7.1/RPMS/netscape-walon-4.74-1mdk.noarch.rpm
832fa8524513f2be4f688983e1483d71  7.1/SRPMS/netscape-4.74-3mdk.src.rpm
29d92c1962b636d0436311b76f980eeb  7.1/SRPMS/netscape-castellano-4.74-1mdk.src.rpm
fd2d46d05243044e4e318f08c163bfba  7.1/SRPMS/netscape-catalan-4.74-1mdk.src.rpm
4ab96db6b7bb17a1f89cdd09ada4a5a6  7.1/SRPMS/netscape-euskara-4.74-1mdk.src.rpm
701f6c3aa7b4b6cd800322b624f040e2  7.1/SRPMS/netscape-francais-4.74-2mdk.src.rpm
4e715744e0e66b487def62a4e750923d  7.1/SRPMS/netscape-walon-4.74-1mdk.src.rpm