HTTP: Mozilla Frame Comment Objects

This signature detects attempts to exploit a known vulnerability in Mozilla family browser. An attacker can create a malicious Web site with Web pages containing dangerous frame comments, which if accessed by a victim, allows the attacker gain control of the victim's client browser.

Extended Description

The Mozilla Foundation has released nine security advisories specifying vulnerabilities in Firefox, SeaMonkey, and Thunderbird. These vulnerabilities allow attackers to: - execute arbitrary code - perform cross-site scripting attacks - inject arbitrary content - gain escalated privileges - crash affected applications and potentially execute arbitrary code. Other attacks may also be possible.

Affected Products

Mozilla thunderbird

References

BugTraq: 21668

CVE: CVE-2006-6504

Short Name
HTTP:STC:MOZILLA:FRAME-COMMENT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2006-6504 Comment Frame Mozilla Objects bid:21668
Release Date
09/22/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Red_hat

Suse

Gentoo

Sun

Rpath

Mozilla

Turbolinux

Avaya

Sgi

Slackware

Ubuntu

Mandriva

Debian

CVSS Score

9.3

Found a potential security threat?