Vulnerability Note VU#427972
Mozilla denial of service vulnerability
Overview
Certain Mozilla products contain a denial-of-service vulnerability.
Description
Certain Mozilla products contain a denial-of-service vulnerability that occurs because of an infinite loop in the js_dtoa function. Mozilla Firefox versions prior to 2.0.0.1, Thunderbird prior to 1.5.0.9, and other Mozilla products may be affected. According to Mozilla Foundation Security Advisory 2006-68:
|
Impact
A remote unauthenticated attacker may be able to cause a denial-of-service condition. |
Solution
Upgrade
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Mozilla | Affected | - | 21 Dec 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.mozilla.org/security/announce/2006/mfsa2006-68.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=358569
- http://secunia.com/advisories/23420/
- http://secunia.com/advisories/23591/
- http://secunia.com/advisories/23598/
- http://secunia.com/advisories/23439/
- http://secunia.com/advisories/23514/
- http://secunia.com/advisories/23618/
- http://www.securityfocus.com/bid/21668
- http://secunia.com/advisories/23988/
- http://www.auscert.org.au/7372
- http://secunia.com/advisories/24390/
- http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-102846-1
Credit
Thanks to Igor Bukanov, Jesse Ruderman, moz_bug_r_a4, Mozilla for providing information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
- CVE IDs: CVE-2006-6499
- Date Public: 19 Dec 2006
- Date First Published: 18 Jan 2007
- Date Last Updated: 04 Jun 2007
- Severity Metric: 0.30
- Document Revision: 41
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.