CVE-2005-3089: Low severity Mozilla Firefox vulnerability
Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3089?
CVE-2005-3089 is classified as a denial-of-service vulnerability that can cause Firefox 1.0.6 to crash.
How do I fix CVE-2005-3089?
To mitigate CVE-2005-3089, users should upgrade to a later version of Mozilla Firefox beyond 1.0.6, preferably 1.0.7 or newer.
Which versions of Firefox are affected by CVE-2005-3089?
CVE-2005-3089 affects Firefox versions 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, and 1.0.6.
Can CVE-2005-3089 be exploited remotely?
While it's unclear if untrusted parties can trigger CVE-2005-3089, it potentially poses a risk for users running the affected versions.
What type of attack is CVE-2005-3089 related to?
CVE-2005-3089 is related to a denial-of-service attack via a Proxy Auto-Config (PAC) script that utilizes an eval statement.