Vulnerability Description
Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| K-Meleon Project | K-Meleon | 0.9.13 |
| Mozilla | Firefox | 1.5.0.2 |
| Netscape | Navigator | 7.2 |
References
- http://secunia.com/advisories/19698Vendor Advisory
- http://secunia.com/advisories/19988Vendor Advisory
- http://secunia.com/advisories/20063Vendor Advisory
- http://secunia.com/advisories/20376Vendor Advisory
- http://secunia.com/advisories/21176Vendor Advisory
- http://secunia.com/advisories/21183Vendor Advisory
- http://secunia.com/advisories/21324Vendor Advisory
- http://secunia.com/advisories/22066Vendor Advisory
- http://securitytracker.com/id?1016202
- http://www.debian.org/security/2006/dsa-1118
- http://www.debian.org/security/2006/dsa-1120
- http://www.debian.org/security/2006/dsa-1134
- http://www.gavinsharp.com/tmp/ImageVuln.htmlPatch
- http://www.mozilla.org/security/announce/2006/mfsa2006-39.htmlVendor Advisory
- http://www.networksecurity.fi/advisories/netscape-view-image.htmlVendor Advisory
FAQ
What is CVE-2006-1942?
CVE-2006-1942 is a vulnerability with a CVSS score of 5.1 (MEDIUM). Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an I...
How severe is CVE-2006-1942?
CVE-2006-1942 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1942?
Check the references section above for vendor advisories and patch information. Affected products include: K-Meleon Project K-Meleon, Mozilla Firefox, Netscape Navigator.