CVE-2006-2778Improper Restriction of Operations within the Bounds of a Memory Buffer in Firefox

16 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
23.3%
top 4.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateMay 1

Description

The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages5 packages

Debianmozilla/thunderbird< 1.5.0.4-1+3
NVDmozilla/firefox1.5.0.3
NVDmozilla/thunderbird1.5.0.3
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.4-1 (sid)
debiandebian/thunderbird< firefox 1.5.dfsg+1.5.0.4-1 (sid)

🔴Vulnerability Details

2
GHSA
GHSA-v3mv-pq4r-vv6g: The crypto2022-05-01
OSV
CVE-2006-2778: The crypto2006-06-02

📋Vendor Advisories

7
Ubuntu
mozilla vulnerabilities2006-07-26
Ubuntu
Thunderbird vulnerabilities2006-07-26
Ubuntu
Firefox vulnerabilities2006-07-25
Ubuntu
Thunderbird vulnerabilities2006-06-14
Ubuntu
firefox vulnerabilities2006-06-09

💬Community

6
Bugzilla
CVE-2006-2778 security flaw2018-08-16
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-07-12
Bugzilla
CVE-2006-2779 multiple Thunderbird issues (CVE-2006-2780, CVE-2006-2781, CVE-2006-2783,CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-28
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-27
Bugzilla
CVE-2006-2783 multiple Seamonkey issues (CVE-2006-2782,CVE-2006-2778,CVE-2006-2776,CVE-2006-2784,CVE-2006-2785,CVE-2006-2786,CVE-2006-2787,CVE-2006-2788)2006-06-27