CVE Vulnerabilities

CVE-2006-4567

Published: Sep 15, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to install arbitrary code on the next update.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 1.5.0.6 (including)
Thunderbird Mozilla * 1.5.0.6 (including)
Red Hat Enterprise Linux 4 RedHat firefox-0:1.5.0.7-0.1.el4 *
Red Hat Enterprise Linux 4 RedHat thunderbird-0:1.5.0.7-0.1.el4 *
Firefox Ubuntu dapper *
Firefox-granparadiso Ubuntu devel *
Lightning-sunbird Ubuntu devel *
Midbrowser Ubuntu devel *
Mozilla-thunderbird Ubuntu dapper *
Mozilla-thunderbird Ubuntu edgy *
Mozilla-thunderbird Ubuntu feisty *

References