HTTP: Mozilla Firefox Javascript Engine tosource Object Remote Code Execution

This signature detects attempts to exploit a known vulnerability in the Mozilla Firefox Javascript Engine. A successful attack can lead to arbitrary code execution.

Extended Description

The Mozilla Foundation has released thirteen security advisories specifying vulnerabilities in Mozilla Firefox, SeaMonkey, and Thunderbird. These vulnerabilities allow attackers to: - execute arbitrary machine code in the context of the vulnerable application - crash affected applications - run arbitrary script code with elevated privileges - gain access to potentially sensitive information - carry out cross-domain scripting attacks. Other attacks may also be possible. The issues described here will be split into individual BIDs as more information becomes available. These issues are fixed in: - Mozilla Firefox 1.5.0.5 - Mozilla Thunderbird 1.5.0.5 - Mozilla SeaMonkey 1.0.3

Affected Products

Mozilla thunderbird

References

BugTraq: 19181

CVE: CVE-2006-3806

Short Name
HTTP:STC:MOZILLA:FF-TOSOURCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2006-3806 Code Engine Execution Firefox Javascript Mozilla Object Remote bid:19181 tosource
Release Date
09/05/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Red_hat

Suse

Gentoo

Sun

Rpath

Mozilla

Avaya

Sgi

Slackware

Ubuntu

Mandriva

Debian

CVSS Score

7.5

Found a potential security threat?