CVE-2006-2920: Input Validation
Published Jun 9, 2006
·Updated
Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.
Affected Software
16 affected components
Sylpheed Sylpheed<=2.2.5
Sylpheed Sylpheed=2.0
Sylpheed Sylpheed=2.0.1
Sylpheed Sylpheed=2.0.2
Sylpheed Sylpheed=2.0.3
Sylpheed Sylpheed=2.1
Sylpheed Sylpheed=2.1.1
Sylpheed Sylpheed=2.1.2
Sylpheed Sylpheed=2.1.3
Sylpheed Sylpheed=2.1.4
Sylpheed Sylpheed=2.1.5
Sylpheed-claws Sylpheed-claws<=2.2.1
Sylpheed-claws Sylpheed-claws=0.9.4
Sylpheed-claws Sylpheed-claws=0.9.5
Sylpheed-claws Sylpheed-claws=0.9.6
Sylpheed-claws Sylpheed-claws=1.0.2
Remediation
Patch Available
Event History
Jun 9, 2006
CVE Published
01:02 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2920?
CVE-2006-2920 is considered a medium severity vulnerability due to its ability to facilitate phishing attacks.
2
How do I fix CVE-2006-2920?
To mitigate CVE-2006-2920, users should upgrade to Sylpheed versions 2.2.6 or higher and Sylpheed-Claws versions 2.2.2 or higher.
3
What systems are affected by CVE-2006-2920?
CVE-2006-2920 affects Sylpheed versions before 2.2.6 and Sylpheed-Claws versions before 2.2.2.
4
What kind of attacks can CVE-2006-2920 lead to?
CVE-2006-2920 can be exploited to conduct phishing attacks by bypassing URI check functionalities.
5
Is there any workaround for CVE-2006-2920 while waiting for a fix?
There are no reliable workarounds for CVE-2006-2920, thus upgrading is strongly recommended.