Published:2005/04/25  Last Updated:2008/05/21

JVN#AF02FB4B
nProtect Netizen has multiple vulnerabilities

Overview

nProtect Netizen contains multiple vulnerabilities.

  • It may fetch update files from an arbitrary site
  • It may download and save malicious files
  • It may cause an abnormal web browser termination

Products Affected

  • nProtect Netizen Ver.4 and earlier

Description

Impact

A remote attacker could lead a user to save a malicious file to the local storage and execute it or cause an abnormal web browser termination.

Solution

Vendor Status

Vendor Status Last Update Vendor Notes
NetMove Corporation Vulnerable 2005/04/25
Metro, Inc. Vulnerable 2005/04/25

References

  1. LAC SNS Advisory No.80
    nProtect:Netizen Arbitrary File Download Vulnerability

JPCERT/CC Addendum

Credit

Keigo Yamazaki of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendors under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2005-000805

Update History