[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-4567Date: (C)2006-09-15   (M)2023-12-22


Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to install arbitrary code on the next update.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1016850
SECTRACK-1016851
BID-20042
http://www.securityfocus.com/archive/1/archive/1/446140/100/0/threaded
SECUNIA-21906
SECUNIA-21916
SECUNIA-21939
SECUNIA-21949
SECUNIA-21950
SECUNIA-22001
SECUNIA-22025
SECUNIA-22055
SECUNIA-22056
SECUNIA-22066
SECUNIA-22074
SECUNIA-22088
SECUNIA-22195
SECUNIA-22210
SECUNIA-22274
SECUNIA-22422
ADV-2006-3617
ADV-2006-3748
ADV-2008-0083
GLSA-200609-19
GLSA-200610-01
HPSBUX02153
MDKSA-2006:168
MDKSA-2006:169
RHSA-2006:0675
RHSA-2006:0677
SSRT061181
SUSE-SA:2006:054
USN-350-1
USN-351-1
USN-352-1
USN-354-1
http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm
http://www.mozilla.org/security/announce/2006/mfsa2006-58.html
https://issues.rpath.com/browse/RPL-640
mozilla-auto-update-gain-access(28950)

CPE    2
cpe:/a:mozilla:firefox:1.5.0.6
cpe:/a:mozilla:thunderbird:1.5.0.6

© SecPod Technologies