CVE-2006-2778 Information
Description
The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments which causes an invalid array index and triggers a buffer overflow.
Reference
http://rhn.redhat.com/errata/RHSA-2006-0609.html http://secunia.com/advisories/20376 http://secunia.com/advisories/20382 http://secunia.com/advisories/20561 http://secunia.com/advisories/20709 http://secunia.com/advisories/21134 http://secunia.com/advisories/21176 http://secunia.com/advisories/21178 http://secunia.com/advisories/21183 http://secunia.com/advisories/21188 http://secunia.com/advisories/21210 http://secunia.com/advisories/21269 http://secunia.com/advisories/21270 http://secunia.com/advisories/21324 http://secunia.com/advisories/21336 http://secunia.com/advisories/21532 http://secunia.com/advisories/21607 http://secunia.com/advisories/21631 http://secunia.com/advisories/22065 http://secunia.com/advisories/22066 http://securitytracker.com/id?1016202 http://securitytracker.com/id?1016214 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102763-1 http://www.debian.org/security/2006/dsa-1118 http://www.debian.org/security/2006/dsa-1120 http://www.debian.org/security/2006/dsa-1134 http://www.gentoo.org/security/en/glsa/glsa-200606-12.xml http://www.gentoo.org/security/en/glsa/glsa-200606-21.xml http://www.kb.cert.org/vuls/id/421529 http://www.mandriva.com/security/advisories?name=MDKSA-2006:143 http://www.mandriva.com/security/advisories?name=MDKSA-2006:145 http://www.mandriva.com/security/advisories?name=MDKSA-2006:146 http://www.mozilla.org/security/announce/2006/mfsa2006-38.html http://www.novell.com/linux/security/advisories/2006_35_mozilla.html http://www.redhat.com/support/errata/RHSA-2006-0578.html http://www.redhat.com/support/errata/RHSA-2006-0594.html http://www.redhat.com/support/errata/RHSA-2006-0610.html http://www.redhat.com/support/errata/RHSA-2006-0611.html http://www.securityfocus.com/archive/1/435795/100/0/threaded http://www.securityfocus.com/archive/1/446657/100/200/threaded http://www.securityfocus.com/archive/1/446658/100/200/threaded http://www.securityfocus.com/bid/18228 http://www.us-cert.gov/cas/techalerts/TA06-153A.html http://www.vupen.com/english/advisories/2006/2106 http://www.vupen.com/english/advisories/2006/3748 http://www.vupen.com/english/advisories/2006/3749 http://www.vupen.com/english/advisories/2007/0058 http://www.vupen.com/english/advisories/2008/0083 https://exchange.xforce.ibmcloud.com/vulnerabilities/26849 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A9703 https://usn.ubuntu.com/296-1/ https://usn.ubuntu.com/296-2/ https://usn.ubuntu.com/297-1/ https://usn.ubuntu.com/297-3/ https://usn.ubuntu.com/323-1/
Share on: