PT-2006-7539 · Mozilla+2 · Libnss-Dev+7

Sync2D

·

Published

1970-01-01

·

Updated

2018-10-17

·

CVE-2006-4568

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libnspr4 versions (affected versions not specified) libnss3 versions (affected versions not specified) Mozilla Firefox versions prior to 1.5.0.7 SeaMonkey versions prior to 1.0.5 libnspr-dev versions (affected versions not specified) libnss-dev versions (affected versions not specified)
Description The issue concerns multiple vulnerabilities in various packages of the Debian GNU/Linux operating system, including libnspr4, libnss3, libnspr-dev, and libnss-dev. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Additionally, a security bypass vulnerability in Mozilla Firefox and SeaMonkey allows remote attackers to inject content into the sub-frame of another site, facilitating spoofing and other attacks. This can be achieved via targetWindow.frames[n].document.open(), which enables attackers to bypass the security model.
Recommendations For libnspr4, consider updating to a version that addresses the vulnerabilities, although the specific version is not specified. For libnss3, consider updating to a version that addresses the vulnerabilities, although the specific version is not specified. For Mozilla Firefox versions prior to 1.5.0.7, update to version 1.5.0.7 or later to resolve the security bypass issue. For SeaMonkey versions prior to 1.0.5, update to version 1.0.5 or later to resolve the security bypass issue. For libnspr-dev, consider updating to a version that addresses the vulnerabilities, although the specific version is not specified. For libnss-dev, consider updating to a version that addresses the vulnerabilities, although the specific version is not specified. As a temporary workaround for the security bypass vulnerability in Mozilla Firefox and SeaMonkey, consider restricting the use of the targetWindow.frames[n].document.open() method until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01278
BDU:2015-01279
BDU:2015-01280
BDU:2015-01281
CVE-2006-4568
DSA-1191-1
DSA-1192-1
DSA-1210
HPSBUX02153
RHSA-2006:0675
RHSA-2006:0676
RHSA-2006_0675
RHSA-2006_0676

Affected Products

Debian
Firefox
Red Hat
Seamonkey
Libnspr-Dev
Libnspr4
Libnss-Dev
Libnss3