PT-2006-7109 · Mozilla+1 · Seamonkey+2

David Bienvenu

+1

·

Published

2006-12-19

·

Updated

2018-10-17

·

CVE-2006-6505

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Thunderbird versions prior to 1.5.0.9 SeaMonkey versions prior to 1.0.7
Description The issue is related to multiple heap-based buffer overflows that can be triggered by remote attackers. This can be achieved through external message modes with long Content-Type headers or long RFC2047-encoded (MIME non-ASCII) headers, potentially allowing the execution of arbitrary code.
Recommendations For Mozilla Thunderbird versions prior to 1.5.0.9, update to version 1.5.0.9 or later. For SeaMonkey versions prior to 1.0.7, update to version 1.0.7 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6505
DSA-1265-1
RHSA-2006:0759
RHSA-2006:0760
RHSA-2006_0759
RHSA-2006_0760

Affected Products

Thunderbird
Red Hat
Seamonkey