Provided and/or discovered by: 1) Doron Rosenberg
2) shutdown
3) Originally discovered by:
* Michael Krax
Additional information provided by:
* Georgi Guninski and L. David Baron.
4) Michael Krax
5) Georgi Guninski
6) moz_bug_r_a4
Changelog: 2005-04-20: Added link to US-CERT vulnerability note.
2005-04-27: Added CVE references.
2005-05-12: New version released. Added information about that the security checks added for vulnerability #3 and #6 in version 1.7.7 can be bypassed. Updated "Description" and "Solution" section.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.