Bug 44106

Summary: zero length file is created or existing file emptied.
Product: [Retired] Red Hat Linux Reporter: Anne CHEYLUS <crouzeix>
Component: netscapeAssignee: Bill Nottingham <notting>
Status: CLOSED WONTFIX QA Contact: David Lawrence <dkl>
Severity: medium Docs Contact:
Priority: medium    
Version: 6.1CC: rvokal
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://generic.labs.pulltheplug.com/zen/evil.html
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2001-06-11 12:30:14 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Anne CHEYLUS 2001-06-11 12:30:10 UTC
From Bugzilla Helper:
User-Agent: Mozilla/4.77 [en] (X11; U; Linux 2.2.19-6.2.1 i686)

Description of problem:
when I load this page, it creates a file in my home directory.
If the file already existed, it is emptied. Here the file name
is zen.was.here, but another name could have been used.

How reproducible:
Always

Steps to Reproduce:
1.launch netscape
2.enter the url http://generic.labs.pulltheplug.com/zen/evil.html
3.check my home directory for the file zen.was.here
	

Actual Results:  A zero length file named zen.was.here was created

Expected Results:  No file created in my home directory.

Additional info:

Comment 1 Bill Nottingham 2001-06-12 17:06:32 UTC
Please report this to netscape at:

http://help.netscape.com/forms/bug-client.html

We don't have the netscape source code; there isn't anything we can do about it.