This application requires Javascript for optimal performance.

Mozilla.Products.Mail.Content.Header.Buffer.Overflow

Release Date

Nov 03, 2011

Severity

critical

Impact

System Compromise: Remote attackers can execute arbitrary code on vulnerable systems.

Description

This indicates detection of one of several Heap Buffer Overflow vulnerabilities in Mozilla Firefox, Thunderbird and SeaMonkey.

The vulnerabilities may allow a remote attacker to execute arbitrary code on a target system, by sending a specially crafted email.

Affected Products

Mozilla Firefox versions prior to 2.0.0.1
Mozilla Firefox versions prior to 1.5.0.9
Mozilla Thunderbird versions prior to 1.5.0.9
Mozilla SeaMonkey versions prior to 1.0.7

Recommended Actions

Upgrade to the latest version, available from the web site.
http://www.mozilla.com/firefox/

Upgrade to the latest version, available from the web site.
http://www.mozilla.com/thunderbird/

Upgrade to the latest version, available from the web site.
http://www.mozilla.org/projects/seamonkey/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-6505

Reference/s

http://www.securityfocus.com/bid/21668 (BugTraq)

Reference: VID-29638