CVE-2006-6954: Input Validation
Published Jan 29, 2007
·Updated
Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
Affected Software
1 affected component
Flock Flock=1.0.7-beta
Event History
Jan 29, 2007
CVE Published
04:28 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6954?
CVE-2006-6954 is classified as a denial of service vulnerability.
2
How does CVE-2006-6954 affect Flock beta 1.0.7?
CVE-2006-6954 allows remote attackers to crash the Flock application by exploiting nested marquee tags in a web page.
3
Who is affected by CVE-2006-6954?
Users of Flock beta version 1.0.7 are at risk from CVE-2006-6954.
4
Can CVE-2006-6954 be exploited remotely?
Yes, CVE-2006-6954 can be exploited remotely through specially crafted web pages.
5
What should I do if I am using Flock beta 1.0.7 in relation to CVE-2006-6954?
It is recommended to discontinue the use of Flock beta 1.0.7 or implement measures to block malicious content.