Overview
A vulnerability exists in the Mozilla JavaScript routine generateCRMFRequest() that may allow a remote attacker to execute arbitrary code.
Description
The crypto object and generateCRMFRequest() The crypto object is used to provide services related to cryptography, such as handling digital certificates. The generateCRMFRequest() routine is used to generate keys for digital certificates. |
Impact
A remote attacker may be able to execute arbitrary code with the privileges of the compromised user. |
Solution
Upgrade |
Disable JavaScript
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported in Mozilla Foundation Security Advisory 2006-24. Mozilla credits shutdown with providing information regarding this issue.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-1728 |
Severity Metric: | 20.45 |
Date Public: | 2006-04-13 |
Date First Published: | 2006-04-17 |
Date Last Updated: | 2007-02-02 15:21 UTC |
Document Revision: | 25 |