First published: Fri Apr 14 2006(Updated: )
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Mozilla Suite | <1.7.13 | |
Mozilla SeaMonkey | <1.0.1 | |
Mozilla Firefox | >=1.5<1.5.0.2 | |
Mozilla Firefox | >=1.0<1.0.8 | |
Ubuntu | =4.10 | |
Ubuntu | =5.04 | |
Ubuntu | =5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1729 is considered critical as it allows remote attackers to read arbitrary files.
To fix CVE-2006-1729, upgrade to Mozilla Firefox version 1.5.0.2 or later, or 1.0.8 or later.
CVE-2006-1729 affects Firefox versions before 1.5.0.2 and 1.0.x before 1.0.8.
Yes, CVE-2006-1729 affects SeaMonkey versions before 1.0.1.
CVE-2006-1729 poses a risk of sensitive data exposure due to unauthorized file access.