CVE-2006-2788: Buffer Overflow
Published Jun 2, 2006
·Updated
Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript code.
Affected Software
24 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=0.10.1
Mozilla Firefox=1.0
Mozilla Firefox=1.0.1
Mozilla Firefox=1.0.2
Mozilla Firefox=1.0.3
Mozilla Firefox=1.0.4
Mozilla Firefox=1.0.5
Mozilla Firefox=1.0.6
Mozilla Firefox=1.0.6
Mozilla Firefox=1.0.7
Mozilla Firefox=1.5
Mozilla Firefox=1.5-beta1
Mozilla Firefox=1.5-beta2
Mozilla Firefox=1.5.0.1
Mozilla Firefox=1.5.0.2
Mozilla Firefox=1.5.0.3
Mozilla Firefox=preview_release
Remediation
Patch Available
Event History
Jun 2, 2006
CVE Published
09:06 PM
Jun 3, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2788?
CVE-2006-2788 has a severity rating that can lead to denial of service and potentially arbitrary code execution.
2
How do I fix CVE-2006-2788?
To fix CVE-2006-2788, upgrade Firefox to the latest version that addresses this vulnerability.
3
Which versions of Firefox are affected by CVE-2006-2788?
CVE-2006-2788 affects Firefox versions 0.8, 0.9, 0.9.1, 1.0.x, and 1.5 beta versions.
4
What type of attack does CVE-2006-2788 facilitate?
CVE-2006-2788 facilitates denial of service attacks and can potentially allow remote code execution.
5
Can CVE-2006-2788 be exploited remotely?
Yes, CVE-2006-2788 can be exploited remotely through specially crafted JavaScript code.