Release DateAug 24, 2006 |
Severityhigh |
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems. |
DescriptionThis indicates an attack attempt against a remote code execution vulnerability in Mozilla Firefox.The vulnerability is caused by an error when the vulnerable software handles a specially crafted eval in an XBL method binding (XBL.method.eval). It allows a remote attacker to execute arbitrary code. |
Affected ProductsMozilla Firefox versions 1.5.0.1 and previous versionsMozilla Firefox versions 1.0.7 and previous versions |
Recommended ActionsUpdate to the latest versions:http://www.mozilla.com/firefox/ |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2006-1735 |
Reference/shttp://www.frsirt.com/english/advisories/2006/1356 (FrSIRT)http://www.securityfocus.com/bid/17516 (BugTraq) |