First published: Wed Dec 20 2006(Updated: )
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | >=1.5<1.5.0.9 | |
Mozilla Firefox | >=2.0<2.0.0.1 | |
Mozilla SeaMonkey | <1.0.7 | |
Ubuntu Linux | =5.10 | |
Ubuntu Linux | =6.06 | |
Ubuntu Linux | =6.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6504 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-6504, users should upgrade to Mozilla Firefox versions 2.0.0.1 or higher, 1.5.0.9 or higher, or SeaMonkey 1.0.7 or higher.
CVE-2006-6504 affects Mozilla Firefox versions 1.5.x before 1.5.0.9, versions 2.x before 2.0.0.1, and SeaMonkey versions before 1.0.7.
Yes, CVE-2006-6504 can be exploited by remote attackers to execute arbitrary code.
CVE-2006-6504 is a memory corruption vulnerability triggered by manipulating SVG comments.