Vulnerability Description
Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 0.8 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2006-0609.html
- http://secunia.com/advisories/21269Vendor Advisory
- http://secunia.com/advisories/21270Vendor Advisory
- http://secunia.com/advisories/21336Vendor Advisory
- http://secunia.com/advisories/21532Vendor Advisory
- http://secunia.com/advisories/21631Vendor Advisory
- http://secunia.com/advisories/22247Vendor Advisory
- http://secunia.com/advisories/22299Vendor Advisory
- http://secunia.com/advisories/22342Vendor Advisory
- http://secunia.com/advisories/22849Vendor Advisory
- http://www.debian.org/security/2006/dsa-1192
- http://www.debian.org/security/2006/dsa-1210
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:143
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:145
- http://www.redhat.com/support/errata/RHSA-2006-0578.html
FAQ
What is CVE-2006-2788?
CVE-2006-2788 is a vulnerability with a CVSS score of 7.5 (HIGH). Double free vulnerability in the getRawDER function for nsIX509Cert in Firefox allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via certain Javascript co...
How severe is CVE-2006-2788?
CVE-2006-2788 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-2788?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.