Overview
Mozilla Firefox web browser and Thunderbird mail client contain a memory corruption vulnerability that may allow a remote attacker to execute arbitrary code.
Description
The Mozilla Firefox QueryInterface method contains a memory corruption vulnerability. According to Mozilla: Calling the QueryInterface method of the built-in Location and Navigator objects causes memory corruption that might be exploitable to run arbitrary code. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. |
Solution
Upgrade |
Disable JavaScript in Firefox
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.mozilla.org/security/announce/mfsa2006-04.html
- http://www.mozilla.com/firefox/releases/1.5.0.1.html
- http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox1.5.0.1
- https://bugzilla.mozilla.org/show_bug.cgi?id=319296
- http://www.securityfocus.com/bid/16476
- http://www.frsirt.com/english/advisories/2006/0413
- http://secunia.com/advisories/18700
- http://secunia.com/advisories/18704
Acknowledgements
These vulnerabilities were reported by Georgi Guninski.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-0295 |
Severity Metric: | 15.46 |
Date Public: | 2006-02-02 |
Date First Published: | 2006-02-07 |
Date Last Updated: | 2006-02-09 19:10 UTC |
Document Revision: | 38 |