CVE-2006-6971: Input Validation
Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP address in (1) dotted-hex, (2) dotted-octal, (3) single decimal integer, (4) single hex integer, or (5) single octal integer format, which is not captured by the blacklist filter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6971?
CVE-2006-6971 is classified as a moderate severity vulnerability.
How does CVE-2006-6971 allow phishing attacks?
CVE-2006-6971 allows attackers to bypass the Phishing Protection mechanism by representing IP addresses in various misleading formats.
Which version of Mozilla Firefox is affected by CVE-2006-6971?
CVE-2006-6971 specifically affects Mozilla Firefox version 2.0.0.1 on Windows.
Is there a patch available for CVE-2006-6971?
A patch is available by updating to a later version of Mozilla Firefox beyond 2.0.0.1.
What types of IP address formats are exploited in CVE-2006-6971?
CVE-2006-6971 exploits IP addresses represented in dotted-hex, dotted-octal, single decimal, single hex, or single octal integer formats.