First published: Fri Sep 15 2006(Updated: )
Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | <=1.0.4 | |
Firefox | <=1.5.0.6 | |
Thunderbird | <=1.5.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4566 is considered a denial of service vulnerability that leads to application crashes.
CVE-2006-4566 affects Mozilla Firefox versions before 1.5.0.7, Thunderbird versions before 1.5.0.7, and SeaMonkey versions before 1.0.5.
To fix CVE-2006-4566, you should upgrade Mozilla Firefox to version 1.5.0.7, Thunderbird to version 1.5.0.7, or SeaMonkey to version 1.0.5 or later.
CVE-2006-4566 can be exploited by remote attackers using crafted JavaScript regular expressions that cause a denial of service.
CVE-2006-4566 was reported in September 2006, highlighting security issues in earlier versions of Mozilla applications.