PT-2006-7539 · Mozilla+2 · Libnss-Dev+7

Sync2D

·

Publicado

1970-01-01

·

Atualizado

2018-10-17

·

CVE-2006-4568

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libnspr4 versions (affected versions not specified) libnss3 versions (affected versions not specified) Mozilla Firefox versions prior to 1.5.0.7 SeaMonkey versions prior to 1.0.5 libnspr-dev versions (affected versions not specified) libnss-dev versions (affected versions not specified)
Description The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including libnspr4, libnss3, libnspr-dev, and libnss-dev. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Additionally, a security bypass vulnerability in Mozilla Firefox and SeaMonkey allows remote attackers to inject content into the sub-frame of another site, facilitating spoofing and other attacks. This can be achieved via targetWindow.frames[n].document.open(), which enables attackers to bypass the security model.
Recommendations For libnspr4, consider updating to a version that addresses the vulnerabilities, although the specific version is not specified. For libnss3, consider updating to a version that addresses the vulnerabilities, although the specific version is not specified. For Mozilla Firefox versions prior to 1.5.0.7, update to version 1.5.0.7 or later to resolve the security bypass issue. For SeaMonkey versions prior to 1.0.5, update to version 1.0.5 or later to resolve the security bypass issue. For libnspr-dev, consider updating to a version that addresses the vulnerabilities, although the specific version is not specified. For libnss-dev, consider updating to a version that addresses the vulnerabilities, although the specific version is not specified. As a temporary workaround for the security bypass vulnerability in Mozilla Firefox and SeaMonkey, consider restricting the use of the targetWindow.frames[n].document.open() method until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01278
BDU:2015-01279
BDU:2015-01280
BDU:2015-01281
CVE-2006-4568
DSA-1191-1
DSA-1192-1
DSA-1210
HPSBUX02153
RHSA-2006:0675
RHSA-2006:0676
RHSA-2006_0675
RHSA-2006_0676

Produtos afetados

Debian
Firefox
Red Hat
Seamonkey
Libnspr-Dev
Libnspr4
Libnss-Dev
Libnss3