|
|
Subscribe / Log in / New account

mozilla: multiple vulnerabilities

Package(s):mozilla CVE #(s):CVE-2005-4134 CVE-2006-0292 CVE-2006-0296
Created:February 2, 2006 Updated:May 4, 2006
Description: Mozilla has three new vulnerabilities. The Javascript interpreter has a problem with dereferencing objects. A user can visit a specially crafted web page which can crash the browser or cause it to execute arbitrary code.

The XULDocument.persist() function has a bug that can be triggered by viewing specially crafted web sites, RDF data can be injected into the localstore.rdf file, allowing arbitrary javascript code to be executed.

The Mozilla history saving mechanism is vulnerable to a denial of service attack, visiting sites with extra-long titles can cause a crash or very slow startup the next time the browser is run.

Alerts:
Ubuntu USN-275-1 mozilla 2006-04-27
Debian DSA-1046-1 mozilla 2006-04-27
Fedora-Legacy FLSA:180036 firefox 2006-02-23
Mandriva MDKSA-2006:037 mozilla-firefox 2006-02-07
Mandriva MDKSA-2006:036 mozilla 2006-02-07
Fedora FEDORA-2006-076 firefox 2006-02-02
Fedora FEDORA-2006-075 mozilla 2006-02-02
Red Hat RHSA-2006:0200-01 firefox 2006-02-02
Red Hat RHSA-2006:0199-01 mozilla 2006-02-02

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds