CVE-2006-2786: Low severity Mozilla Firefox vulnerability
HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2786?
CVE-2006-2786 is classified as a moderate severity vulnerability.
How do I fix CVE-2006-2786?
To fix CVE-2006-2786, update Mozilla Firefox and Mozilla Thunderbird to version 1.5.0.4 or later.
Which versions of Mozilla Firefox are affected by CVE-2006-2786?
Versions of Mozilla Firefox prior to 1.5.0.4 are affected by CVE-2006-2786.
Which versions of Mozilla Thunderbird are impacted by CVE-2006-2786?
Mozilla Thunderbird versions prior to 1.5.0.4 are impacted by CVE-2006-2786.
What type of vulnerability is CVE-2006-2786?
CVE-2006-2786 is an HTTP response smuggling vulnerability.