CVE-2006-5877: High severity Ubuntu Ubuntu Linux vulnerability
Published Feb 23, 2007
·Updated
The enigmail extension before 0.94.2 does not properly handle large, encrypted file e-mail attachments, which allows remote attackers to cause a denial of service (crash), as demonstrated with Mozilla Thunderbird.
Affected Software
4 affected components
Ubuntu Ubuntu Linux<=5.10
Ubuntu Ubuntu Linux<=6.06_lts
Ubuntu Ubuntu Linux<=6.10
Enigmail Enigmail<=0.92.0
Remediation
Patch Available
Event History
Feb 23, 2007
CVE Published
09:28 PM
Data Sourced
09:28 PM
DescriptionWeaknessAffected Software
Feb 24, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-5877?
CVE-2006-5877 is classified as a denial of service vulnerability that can lead to crashes.
2
How do I fix CVE-2006-5877?
To fix CVE-2006-5877, upgrade to Enigmail version 0.94.2 or later.
3
What software is affected by CVE-2006-5877?
CVE-2006-5877 specifically affects Enigmail versions prior to 0.94.2.
4
Can CVE-2006-5877 be exploited remotely?
Yes, CVE-2006-5877 can be exploited by remote attackers through malicious email attachments.
5
Is CVE-2006-5877 relevant for all users of Enigmail?
CVE-2006-5877 is particularly relevant for users of Enigmail versions prior to 0.94.2.