First published: Fri Apr 14 2006(Updated: )
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Mozilla Suite | <1.7.13 | |
Mozilla Thunderbird | >=1.0<1.0.8 | |
Mozilla SeaMonkey | <1.0.1 | |
Mozilla Firefox | >=1.5<1.5.0.2 | |
Mozilla Firefox | >=1.0<1.0.8 | |
Mozilla Thunderbird | >=1.5<1.5.0.2 | |
Debian GNU/Linux | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1724 has a high severity level due to its potential for causing a denial of service and executing arbitrary code.
To fix CVE-2006-1724, update to Firefox version 1.5.0.2 or later, Thunderbird version 1.0.8 or later, SeaMonkey version 1.0.1 or later, or Mozilla Suite version 1.7.13 or later.
CVE-2006-1724 affects Firefox versions before 1.5.0.2, Thunderbird versions before 1.0.8, Mozilla Suite versions before 1.7.13, and SeaMonkey versions before 1.0.1.
CVE-2006-1724 allows remote attackers to cause a denial of service crash and potentially execute arbitrary code through specific DHTML-related attack vectors.
Yes, a public security announcement regarding CVE-2006-1724 was made by Mozilla to address the vulnerability.