First published: Mon Jan 29 2007(Updated: )
Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flock Flock | =1.0.7-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6954 is classified as a denial of service vulnerability.
CVE-2006-6954 allows remote attackers to crash the Flock application by exploiting nested marquee tags in a web page.
Users of Flock beta version 1.0.7 are at risk from CVE-2006-6954.
Yes, CVE-2006-6954 can be exploited remotely through specially crafted web pages.
It is recommended to discontinue the use of Flock beta 1.0.7 or implement measures to block malicious content.