PC Takeover Flaw in Mozilla, Netscape
Security researchers have discovered a "highly critical" security hole in the Netscape and Mozilla browsers that puts users at risk of computer takeover.
According to an advisory from iDefense, the vulnerability is caused by an integer overflow within the SOAPParameter object's constructor.
SOAPParameter objects handle support for SOAP
The company warned that the flaw can be exploited via specially created Web pages containing malicious Javascript. Browser products affected include Mozilla 1.6; and Netscape versions 7.0 and 7.1.
The open-source Mozilla Foundation has released an update to fix the flaw.
"Netscape have not released any information indicating they are intending to release future versions of the Netscape browser, and no longer have any developers working on this project," iDefense said.
The research firm recommends that users disable Javascript in the browser as a workaround.