Reported August 7, 2000 by Dan Brumleve

VERSIONS EFFECTED
Netscape Communicator 4.05through 4.74

DESCRIPTION

Netscape's Java distribution has two classes (netscape.net.URLConnection and netscape.net.URLInputStream) that allow remote access to locally stored files without the user's knowledge.

In addition, by using other flaws in Netscapes implementation of Java, Communicator can be made to start a Web server for public access without the user's knowledge and without producing an exception to the security policy.

VENDOR RESPONSE

Netscape has issued a fix for this problem, which is located on their security Web page. Users have reported that Mozilla M15 (Netscape 6 Preview 1) and M16 are immune to these problems.

CREDIT
Discovered by Dan Brumleve