CVE Vulnerabilities

CVE-2006-2778

Published: Jun 02, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*1.5.0.3 (including)
ThunderbirdMozilla*1.5.0.3 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.2-0.1.0.EL3*
Red Hat Enterprise Linux 4RedHatdevhelp-0:0.10-0.2.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.3-0.el4.1*
Red Hat Enterprise Linux 4RedHatfirefox-0:1.5.0.5-0.el4.1*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.5-0.el4.1*
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
FirefoxUbuntudapper*
Firefox-granparadisoUbuntudevel*
Lightning-sunbirdUbuntudevel*
MidbrowserUbuntudevel*
Mozilla-thunderbirdUbuntudapper*
Mozilla-thunderbirdUbuntuedgy*
Mozilla-thunderbirdUbuntufeisty*
XulrunnerUbuntudevel*
XulrunnerUbuntuedgy*
XulrunnerUbuntufeisty*

References