|
 |
|
Mozilla Firefox and SeaMonkey Multiple Vulnerabilities
|
|
|
|
|
Secunia Advisory:
|
SA22722
|
|
|
Release Date:
|
2006-11-08
|
|
Last Update:
|
2006-11-09
|
|
|
Critical:
|

Highly critical
|
|
Impact:
|
Security Bypass Cross Site Scripting DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Mozilla Firefox 1.x Mozilla SeaMonkey 1.0.x
|
| | CVE reference: | CVE-2006-5462 (Secunia mirror) CVE-2006-5463 (Secunia mirror) CVE-2006-5464 (Secunia mirror) CVE-2006-5747 (Secunia mirror) CVE-2006-5748 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Some vulnerabilities have been reported in Mozilla Firefox and Mozilla SeaMonkey, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, and potentially compromise a vulnerable system.
1) The bundled Network Security Services (NSS) library contains an incomplete fix for the RSA signature verification vulnerability reported in MFSA 2006-60.
For more information:
SA21903
2) An error exists within the handling of Script objects. This can potentially be exploited to execute arbitrary JavaScript bytecode by modifying already running Script objects.
3) Some unspecified errors in the layout engine and memory corruption errors in the JavaScript engine can be exploited to crash the application and may allow execution of arbitrary code.
4) An unspecified error within XML.prototype.hasOwnProperty can potentially be exploited to execute arbitrary code.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
Solution: Update to Mozilla Firefox 1.5.0.8 and SeaMonkey 1.0.6.
Provided and/or discovered by: 1) Ulrich Kuehn
2) shutdown
3) Jesse Ruderman, Martijn Wargers, and Igor Bukanov
4) shutdown
Changelog: 2006-11-09: Added links to US-CERT vulnerability notes.
Original Advisory: MFSA-2006-65:
http://www.mozilla.org/security/announce/2006/mfsa2006-65.html
MFSA-2006-66:
http://www.mozilla.org/security/announce/2006/mfsa2006-66.html
MFSA-2006-67:
http://www.mozilla.org/security/announce/2006/mfsa2006-67.html
Other References: US-CERT VU#815432:
http://www.kb.cert.org/vuls/id/815432
US-CERT VU#495288:
http://www.kb.cert.org/vuls/id/495288
US-CERT VU#390480:
http://www.kb.cert.org/vuls/id/390480
US-CERT VU#335392:
http://www.kb.cert.org/vuls/id/335392
US-CERT VU#714496:
http://www.kb.cert.org/vuls/id/714496
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
53 Related Secunia Security Advisories, displaying 10
|
|
|
1. Firefox "-chrome" Parameter Security Issue
|
|
2. Mozilla SeaMonkey Multiple Vulnerabilities
|
|
3. Firefox "OnKeyDown" Event Focus Weakness
|
|
4. Mozilla SeaMonkey Multiple Vulnerabilities
|
|
5. Mozilla Firefox / Seamonkey "resource://" Information Disclosure
|
|
6. Mozilla Firefox Multiple Vulnerabilities
|
|
7. Mozilla SeaMonkey Multiple Vulnerabilities
|
|
8. Mozilla Firefox Multiple Vulnerabilities
|
|
9. Mozilla Firefox "locations.hostname" DOM Property Handling Vulnerability
|
|
10. Mozilla SeaMonkey Multiple Vulnerabilities
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|