CVE-2006-1942: Medium severity K-meleon Project K-meleon vulnerability
Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1942?
CVE-2006-1942 is considered a moderate severity vulnerability that allows remote attackers to access local files on a user's system.
How do I fix CVE-2006-1942?
To fix CVE-2006-1942, upgrade to Mozilla Firefox version 1.5.0.4 or later, or use a different browser that is not affected.
What versions of software are affected by CVE-2006-1942?
CVE-2006-1942 affects Mozilla Firefox versions before 1.5.0.4, Netscape Navigator versions 7.2, 8.0.4, and 8.1, and K-Meleon 0.9.13.
Can exploitation of CVE-2006-1942 lead to sensitive data exposure?
Yes, exploitation of CVE-2006-1942 can potentially expose sensitive local files to remote attackers.
What types of attacks are possible with CVE-2006-1942?
CVE-2006-1942 enables remote attackers to perform user-assisted attacks that can lead to unauthorized access of local files.