CVE-2005-2968: High severity Mozilla Firefox vulnerability
Published Sep 20, 2005
·Updated
Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.
Affected Software
2 affected components
Mozilla Firefox=1.0.6
Mozilla Mozilla=1.7.10
Remediation
Patch Available
Patch Available
Event History
Sep 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2968?
CVE-2005-2968 has a moderate severity rating due to the potential for arbitrary command execution.
2
How do I fix CVE-2005-2968?
To fix CVE-2005-2968, upgrade to a version of Firefox higher than 1.0.6 or Mozilla higher than 1.7.10.
3
What software versions are affected by CVE-2005-2968?
CVE-2005-2968 affects Firefox version 1.0.6 and Mozilla version 1.7.10.
4
What type of attack does CVE-2005-2968 enable?
CVE-2005-2968 enables attackers to execute arbitrary commands through malicious URLs.
5
How does CVE-2005-2968 exploit the command line?
CVE-2005-2968 exploits the command line by allowing shell metacharacters in URLs that are sent unfiltered to bash.