PT-2005-3810 · Mozilla+1 · Mozilla Firefox+2
Peter Zelezny
·
Published
2005-09-20
·
Updated
2017-10-11
·
CVE-2005-2968
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Firefox version 1.0.6
Mozilla version 1.7.10
Description
The issue allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line. This URL is sent unfiltered to bash, potentially leading to command execution.
Recommendations
For Firefox version 1.0.6, update to a version that filters shell metacharacters in URLs provided on the command line.
For Mozilla version 1.7.10, update to a version that filters shell metacharacters in URLs provided on the command line.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox
Mozilla Firefox
Red Hat